On the Privacy-Preserving Capabilities of PAVE Specifications in Learnware
On the Privacy-Preserving Capabilities of PAVE Specifications in Learnware
Hao-Yi Lei, Jin-Hui Wu, Zhi-Hao Tan, Zhi-Hua Zhou
Proceedings of the Thirty-Fifth International Joint Conference on Artificial Intelligence
Main Track. Pages 4465-4473.
https://doi.org/10.24963/ijcai.2026/497
The learnware paradigm supports model reuse by pairing each submitted model with a specification, a lightweight representation used by the learnware dock system to identify, match, and reuse models without accessing raw data. While specifications are essential for learnware identification, they are also data-dependent public artifacts and it is not clear whether they reveal private information. Recently, the Parameter Vector (PAVE) specification has been proposed and shown to be effective for learnwares, yet its privacy properties remain largely unexplored. In this paper, we provide the first theoretical privacy analysis for PAVE. Specifically, we first formalize two specification-induced risks in the learnware paradigm: the disclosure risk of the released specification and the amplification risk that the specification may strengthen attacks against the released model. Second, we characterize when compact PAVE releases admit intrinsic differential privacy (DP): under natural structural conditions of learnware docks, the compact PAVE specification satisfies an (ε, δ)-DP guarantee without explicit additive noise through a Gaussian-sketch view of stable parameter variations, and for regimes outside these conditions, we further provide DP-Stabilized-PAVE as a certified differentially private variant. Third, we show that the resulting DP guarantees control both disclosure risk and amplification risk, and we analyze the induced privacy--utility trade-off to guide effective learnware identification while preserving privacy.
Keywords:
Machine Learning: Learnware/model reuse/transfer learning
Multidisciplinary Topics and Applications: Security and privacy
