[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83932-en":3,"doc-seo-83932-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83932,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Learning Only What Valid Adapters Can Express","Parameter-efficient fine-tuning still enables broad behavior-changing updates, leaving room for poisoned objectives to be represented and optimized. The study constrains adaptation to a low-dimensional subspace estimated from a trusted pool of existing task adapters. Experiments on flan-t5-large with 196 public LoRA adapters show that only a small fraction of weight norm is functionally relevant, subspace-restricted gradients match clean LoRA performance, and constrained learning blocks poisoning with strong out-of-distribution loss separation. The approach trades peak plasticity for robustness under the stated trusted-pool assumption.","arXiv :2607 .05300v 1 [ cs .LG] 6 Jul 2026  \nLearning Only What Valid Adapters Can Express: Subspace-Constrained Adaptation Against Fine-Tuning Poisoning  \nFabien Polly∗  \nJuly 2026  \nAbstract  \nParameter-efficient fine-tuning still leaves a broad space of behavior-changing updates reachable, so a poisoned objective can be represented and optimized. We study an alternative: adaptation constrained to the subspace estimated from a trusted pool of existing task adapters. On flan-t5-large with 196 public LoRA adapters, we show that (1) the functionally relevant content of an adapter lies in a lowdimensional shared subspace, 30 to 38 percent of its weight norm being redundant under the evaluated task distributions; (2) gradient adaptation restricted to 128 coordinates on this subspace matches full LoRA fine-tuning on clean classification data, while under targeted label inversion LoRA collapses to 3–26 percent exact match and the constrained learner keeps 62–96 percent on the tasks the pool covers;  \n(3) the constrained learner cannot fit corrupted data, its adaptation loss separating clean from garbage by two orders of magnitude (120 ×), an out-of-distribution signal for free; and (4) against an adaptive backdoor attacker who optimizes within the subspace, the attack is blocked (8 percent success versus 100 for LoRA) on the task where its target behavior is unlike anything in the pool, and only partially blocked (85 percent) when the target coincides with a common pool behavior. On these two tasks the outcome is consistent with how close the target is to the pool’s directions, which suggests but does not establish a pool-relative boundary. The mechanism trades peak plasticity for these properties: on tasks the pool covers poorly, unconstrained fine-tuning wins, and the guarantee assumes the pool itself is trusted. Code and data are public.  \n1 Introduction  \nFine-tuning is an attack surface. A consumer medical assistant maliciously personalized to recommend a dangerous dose, a corporate model taught by a poisoned document to exfiltrate its database on a trigger word, a brand chatbot absorbing toxic user chats, a model fine-tuned on scraped web text that a coordinated edit campaign has seeded with falsehoods: every adaptation on data the operator does not fully control is a vulnerability. A few hundred corrupted instructions suffice to compromise an aligned model [12, 8] . Existing defenses inspect the data (filtering, influence functions) or dampen the update (regularization); all are heuristic in the sense that a successful attack remains expressible, the defense just makes it harder to reach.  \nWe study a defense that shrinks expressibility instead. The weight updates a model acquires when learning legitimate tasks do not fill update space; they concentrate in a low-dimensional shared subspace. If adaptation is constrained to that subspace, the set of reachable updates is greatly reduced, and we find empirically that the poisoned objectives in our threat models require updates outside it: they cannot befit, and that failure is visible in the training loss. We are careful not to overclaim: a subspace spanned by legitimate adapters can still contain far extrapolations and combinations unlike any single adapter, so this is empirical protection against the attacks we test, not a proof that no harmful behavior is expressible (Section 5) .  \nWe instantiate the idea with the affine span of a public pool of LoRA adapters, and evaluate it on a real language model against an equal-data, equal-optimization-step LoRA baseline. Our contributions: (1) an analysis of the functional geometry of 196 public adapters showing that 30 to 38 percent of an adapter’s weight norm is functionally redundant under the evaluated distributions; (2) a constrained adaptation mechanism  \n∗ Independent researcher. Code and data: [https://github.com/infinition/z-manifold](https://github.com/infinition/z-manifold)  \nwith 128 trainable coordinates that matches LoRA","cbCaikHWrk68Nv1r","https://ap.wps.com/l/cbCaikHWrk68Nv1r","pdf",510286,7,1,10,"English","en",105,"# Introduction\n# Related work","[{\"question\":\"What problem does the document address in fine-tuning systems?\",\"answer\":\"It studies how fine-tuning can be exploited as an attack surface through poisoned objectives, even when parameter-efficient methods like LoRA are used.\"},{\"question\":\"How does the proposed defense restrict model updates?\",\"answer\":\"Adaptation is constrained to an estimated low-dimensional subspace formed from the affine span of existing task adapters from a trusted pool.\"},{\"question\":\"How does restricting adaptation affect poisoning and detection?\",\"answer\":\"Under targeted label inversion, unconstrained LoRA collapses to a small fraction of exact matches, while the constrained learner maintains high performance on pool-covered tasks; corrupted data fails to be fit, and adaptation loss separates clean from garbage by about two orders of magnitude.\"}]",1784191522,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"learning-only-what-valid-adapters-can-express","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/learning-only-what-valid-adapters-can-express/83932/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the document address in fine-tuning systems?","Question",{"text":76,"@type":77},"It studies how fine-tuning can be exploited as an attack surface through poisoned objectives, even when parameter-efficient methods like LoRA are used.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the proposed defense restrict model updates?",{"text":81,"@type":77},"Adaptation is constrained to an estimated low-dimensional subspace formed from the affine span of existing task adapters from a trusted pool.",{"name":83,"@type":74,"acceptedAnswer":84},"How does restricting adaptation affect poisoning and detection?",{"text":85,"@type":77},"Under targeted label inversion, unconstrained LoRA collapses to a small fraction of exact matches, while the constrained learner maintains high performance on pool-covered tasks; corrupted data fails to be fit, and adaptation loss separates clean from garbage by about two orders of magnitude.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,120,123,128,131,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":22,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":107,"slug":137},19,"General","general"]