NTH

How Many Bits Can an Adapter Write? Measuring the Capacity and Memorization of Parameter-Efficient Fine-Tuning

AuthorsKaizhen Tan, Heqing Du, Yang Feng

July 26, 2026 3 min read
Watch on YouTube
The one-line take

This paper measures how many bits of data LoRA adapters can secretly store and finds that their memorization depends more on where parameters are placed than on how many there are.

Key results

3.6
Full-model memorization rate

Full fine-tuning stores about 3.6 bits per parameter.

2.8
Maximum adapter rate

LoRA adapters plateau between 1.7 and 2.8 bits per trainable parameter.

2.43
Placement-dependent capacity

With about 37K parameters, capacity reaches 2.43 bits per parameter when updates are placed in the MLP.

98%
Pretrained-base memorization

The same adapter memorizes 98% of random data on a WikiText-pretrained base.

29%
Random-base memorization

The same adapter memorizes 29% on a randomly initialized base.

11
Rank-related exposure increase

Moving from rank 16 to rank 64 increases canary exposure by 11 bits.

What the paper found

Kaizhen Tan, Heqing Du, and Yang Feng of Carnegie Mellon University and Columbia University introduce a compression-based instrument for measuring how many information bits a parameter-efficient adapter actually writes into a frozen model. Using 64-token uniformly random sequences over a 2,048-symbol vocabulary, yielding 704 bits per sequence, they separate memorization from prediction and show that LoRA adapters store substantially less than full fine-tuning: full models reach 3.6 bits per parameter, while adapters plateau between 1.7 and 2.8 bits per trainable parameter under a matched 16,000-step budget. Capacity is not determined by parameter count alone: with about 37K trainable parameters, moving the update from attention to the MLP changes capacity from 1.30 to 2.43 bits per parameter, while reduced-precision storage has little effect. The frozen base also matters dramatically: the same adapter memorizes 29% of random data on a randomly initialized base, versus 98% on a WikiText-pretrained base, while full fine-tuning of the random base reaches 99%. On Qwen2.5-0.5B, canary exposure tracks written bits rather than nominal rank; increasing rank from 16 to 64 raises exposure by 11 bits. Finally, comparing supervised fine-tuning with GRPO on verifiable rewards at similar task performance, supervised training continues writing training-specific information and copies injected secrets, whereas GRPO’s excess behavior-write signal remains indistinguishable from zero. The results frame LoRA adapters, including those shared through model hubs or federated systems, as measurable data-bearing artifacts rather than harmless skill patches.

Original abstract

A LoRA adapter is a few megabytes that almost everyone treats as a skill rather than a record of the data behind it. We put that assumption on a scale. Extending compression-based memorization analysis to the frozen-base setting, we measure directly, in bits, how much a low-rank adapter writes into a model it never changes. The answer is both smaller than full fine-tuning and less lawful than parameter counting would predict. Adapters store a couple of bits per trainable parameter, well short of a full model's budget, but that figure turns less on how many parameters an adapter carries than on where they sit. Move the same parameter budget from attention into the MLP and it holds nearly twice as much; strip the frozen base of its structure and the capacity all but disappears. Applied to realistic fine-tunes of Qwen2.5, the same instrument shows privacy leakage rising with the bits an adapter writes rather than the parameters it nominally has, and it draws a clean line between supervised and reinforcement learning: the secrets that supervised fine-tuning copies down verbatim, an adapter trained on verifiable rewards never records. Measuring what fine-tuning writes, rather than attacking it after the fact, turns a piece of folklore into a quantity one can design against.

Read the original paper

More in Efficient AI

Browse all 55 papers →
01Efficiency

Decoding Looped Transformers Better for (Almost) Free

Weihao Liu, Huangjie Zheng, Tianrong Chen, Rohit Dilip, Richard He Bai, Yizhu Jiao, Yuyang Wang, Ruixiang Zhang

LoopCD turns the partially computed states of looped Transformers into free guidance, improving accuracy while often cutting inference compute nearly in half.

Read analysis
02Efficiency

Scaling Laws for Looped Mixture of Experts

Yanbei Chen, Anirudh Goyal, Raghuraman Krishnamoorthi

This work develops scaling laws that explain how looping and sparse experts can be combined to build more capable models with less training and inference compute.

Read analysis