VaultGemma: A Differentially Private Gemma Model
Amer Sinha, Thomas Mesnard, Ryan McKenna, Daogao Liu, Christopher A. Choquette-Choo, Yangsibo Huang, Da Yu, George Kaissis, Zachary Charles, Ruibo Liu, Lynn Chua, Pritish Kamath, Pasin Manurangsi, Steve He, Chiyuan Zhang, Badih Ghazi, Borja De Balle Pigem, Prem Eruvbetine, Tris Warkentin, Armand Joulin, Ravi Kumar
TL;DR
VaultGemma addresses the risk of verbatim memorization in pretraining large language models by training an open-weight 1B parameter decoder-only transformer with end-to-end differential privacy. The approach combines DP-SGD, repeated-document packing, Truncated Poisson Subsampling, and principled privacy accounting, anchored by novel DP scaling laws that explicitly model the optimal learning rate and extrapolate loss across iterations. Key findings include an $\epsilon \le 2.0$, $\delta \le 1.1\times 10^{-10}$ sequence-level DP guarantee and zero memorization detectable in DP Gemma, demonstrating that private LLMs can approach non-private utility with a clear roadmap for improvement. By releasing VaultGemma and its training methodology, the work provides a practical baseline to accelerate privacy-preserving AI research and applications, while acknowledging the remaining utility gap to non-private models.
Abstract
We introduce VaultGemma 1B, a 1 billion parameter model within the Gemma family, fully trained with differential privacy. Pretrained on the identical data mixture used for the Gemma 2 series, VaultGemma 1B represents a significant step forward in privacy-preserving large language models. We openly release this model to the community
