How Many Bits Can an Adapter Write? Measuring the Capacity and Memorization of Parameter-Efficient Fine-Tuning
AuthorsKaizhen Tan, Heqing Du, Yang Feng
Resources
This paper measures how many bits of data LoRA adapters can secretly store and finds that their memorization depends more on where parameters are placed than on how many there are.
Key results
Full fine-tuning stores about 3.6 bits per parameter.
LoRA adapters plateau between 1.7 and 2.8 bits per trainable parameter.
With about 37K parameters, capacity reaches 2.43 bits per parameter when updates are placed in the MLP.
The same adapter memorizes 98% of random data on a WikiText-pretrained base.
The same adapter memorizes 29% on a randomly initialized base.
Moving from rank 16 to rank 64 increases canary exposure by 11 bits.
What the paper found
Kaizhen Tan, Heqing Du, and Yang Feng of Carnegie Mellon University and Columbia University introduce a compression-based instrument for measuring how many information bits a parameter-efficient adapter actually writes into a frozen model. Using 64-token uniformly random sequences over a 2,048-symbol vocabulary, yielding 704 bits per sequence, they separate memorization from prediction and show that LoRA adapters store substantially less than full fine-tuning: full models reach 3.6 bits per parameter, while adapters plateau between 1.7 and 2.8 bits per trainable parameter under a matched 16,000-step budget. Capacity is not determined by parameter count alone: with about 37K trainable parameters, moving the update from attention to the MLP changes capacity from 1.30 to 2.43 bits per parameter, while reduced-precision storage has little effect. The frozen base also matters dramatically: the same adapter memorizes 29% of random data on a randomly initialized base, versus 98% on a WikiText-pretrained base, while full fine-tuning of the random base reaches 99%. On Qwen2.5-0.5B, canary exposure tracks written bits rather than nominal rank; increasing rank from 16 to 64 raises exposure by 11 bits. Finally, comparing supervised fine-tuning with GRPO on verifiable rewards at similar task performance, supervised training continues writing training-specific information and copies injected secrets, whereas GRPO’s excess behavior-write signal remains indistinguishable from zero. The results frame LoRA adapters, including those shared through model hubs or federated systems, as measurable data-bearing artifacts rather than harmless skill patches.
Original abstract
A LoRA adapter is a few megabytes that almost everyone treats as a skill rather than a record of the data behind it. We put that assumption on a scale. Extending compression-based memorization analysis to the frozen-base setting, we measure directly, in bits, how much a low-rank adapter writes into a model it never changes. The answer is both smaller than full fine-tuning and less lawful than parameter counting would predict. Adapters store a couple of bits per trainable parameter, well short of a full model's budget, but that figure turns less on how many parameters an adapter carries than on where they sit. Move the same parameter budget from attention into the MLP and it holds nearly twice as much; strip the frozen base of its structure and the capacity all but disappears. Applied to realistic fine-tunes of Qwen2.5, the same instrument shows privacy leakage rising with the bits an adapter writes rather than the parameters it nominally has, and it draws a clean line between supervised and reinforcement learning: the secrets that supervised fine-tuning copies down verbatim, an adapter trained on verifiable rewards never records. Measuring what fine-tuning writes, rather than attacking it after the fact, turns a piece of folklore into a quantity one can design against.
Read the original paperMore in Efficient AI
Browse all 55 papers →Decoding Looped Transformers Better for (Almost) Free
Weihao Liu, Huangjie Zheng, Tianrong Chen, Rohit Dilip, Richard He Bai, Yizhu Jiao, Yuyang Wang, Ruixiang Zhang
LoopCD turns the partially computed states of looped Transformers into free guidance, improving accuracy while often cutting inference compute nearly in half.
Scaling Laws for Looped Mixture of Experts
Yanbei Chen, Anirudh Goyal, Raghuraman Krishnamoorthi
This work develops scaling laws that explain how looping and sparse experts can be combined to build more capable models with less training and inference compute.
When Fancy Eviction Fails: Rethinking Cache Replacement For LLM Prefix Reuse
Yiyu Liu, Minlan Yu, Juncheng Yang
For LLM prefix caches, simple recency may beat fancy eviction rules, especially when workloads follow predictable session patterns.