
Constraining Fine-tuning to Trusted LoRA Subspaces
A new research approach prevents model poisoning by restricting fine-tuning to a subspace defined by trusted LoRA adapters. This makes malicious behavior geometrically unreachable while preserving the model's ability to learn legitimate tasks.





