The Loss Does Not Define the Private Optimizer: Query Semantics in Robust Fine-Tuning
Abstract
Modern ML systems may require several forms of protection simultaneously, even when these protections intervene at the same stage of training. In such cases, their interaction is not necessarily modular. We study this problem at the intersection of differential privacy and robustness to adversarial perturbations. Several natural strategies can be used to integrate a composite robustness objective into private optimization, yet the consequences of this choice remain poorly understood. We show that different strategies can yield different private optimizers even when they share the same objective and privacy calibration. Through a geometric analysis, we characterize when and why these strategies modify the optimization signal in fundamentally different ways. Controlled experiments with TRADES as a representative composite robustness objective confirm that these differences materially affect adversarial robustness when sensitivity and noise calibration are matched. The separation persists under both standard clipping and the smooth AUTO-S mechanism, suggesting that it reflects a more general interaction between objective composition and private optimization rather than a peculiarity of a particular clipping rule.