Pith. sign in

REVIEW 3 major objections 4 minor 1 cited by

Federated Large Language Models: Feasibility, Robustness, Security and Future Directions

T0 review · 3 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read This survey organizes federated large language models into four questions—feasibility, robustness, security, and future directions—and concludes that the open problems are robustness and security.

desk verdict A useful but sloppy survey: the taxonomy and gap analysis are worth reading, but the citation errors and missing search protocol mean it needs revision before I'd trust it as a reference. read the letter →

arxiv 2505.08830 v1 pith:3TDYIH3J submitted 2025-05-13 cs.CR cs.AI

classification cs.CRcs.AI
keywords federatedlearninglargelanguagemodelsparameter-efficientfine-tuningheterogeneityprivacysecuritymachineunlearning
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper is a survey of federated large language models (FLLM), the practice of training or fine-tuning an LLM across many data holders without centralizing their private data. Its organizing thesis is that the field can be mapped onto four questions: whether FLLM can be done efficiently (feasibility), whether it survives differences among participants and their data (robustness), whether it resists attackers and protects privacy (security), and what remains to be done (future directions). The survey's central claim is that feasibility is largely demonstrated in academic settings through parameter-efficient fine-tuning, while robustness and security are the underdeveloped parts: data and task heterogeneity have few solutions, and most security work is concentrated on backdoor attacks. The practical stake is that FLLM is viable as a research program, but its deployment will be decided by reliability and safety rather than by the ability to train at all.

What carries the argument

The paper's machinery is a four-axis taxonomy—feasibility, robustness, security, and future directions—used to sort the FLLM literature, with its overview figure using darker circles to encode how many studies each sub-topic has. The feasibility axis is itself organized around Federated Parameter-Efficient Fine-Tuning (FedPEFT), which freezes most of the LLM and trains only small modules such as low-rank adapters (LoRA, where a weight update is written as $\Delta W = B A$ with low-rank $B$ and $A$) or inserted adapters; this is the mechanism that makes client-side fine-tuning affordable. Robustness is organized around three kinds of heterogeneity—resource, data, and task—and security around a list of attacks (membership inference, data reconstruction, jailbreaking, prompt injection, long-tailed data leakage, poisoning, backdoors) and defenses. The taxonomy does the work: it lets the authors claim that most publications sit in the feasibility cell and that robustness and security cells are comparatively empty.

What would settle it

Run a systematic literature search with a stated query and date range that counts papers per taxonomy cell: if the data- and task-heterogeneity cells and the security cell turn out to contain a substantial body of FLLM-specific work omitted here—for example, more than a dozen studies of FLLM-specific gradient or poisoning attacks—then the survey's central gap claim would need revision.

Watch

Extended reading notes

Core claim

The paper's discovery is a structured map of the FLLM literature. It finds that the field is uneven: most published work addresses feasibility, using full-parameter fine-tuning, parameter-efficient fine-tuning (PEFT), prompt tuning, model compression, split learning, and zeroth-order optimization to bring the cost of client-side training down; the paper reads this as showing that FLLM is achievable in the lab, though still far from ordinary devices. Robustness work exists but clusters around resource heterogeneity—clients with different compute, memory, and bandwidth—with comparatively little on data heterogeneity or the task heterogeneity that arises when clients run different NLP tasks on one shared model. On security, the paper reports that attacks and defenses specific to FLLM are scarce, that certain FL and LLM attacks do not transfer unchanged (for example, membership inference is often close to random for large models), and that backdoors are the most studied threat. Its closing claim is that the field's next phase should concentrate on robustness and security, plus the new demands of few-shot learning, machine unlearning, and intellectual-property protection.

Load-bearing premise

The survey's conclusions stand or fall on whether its chosen references are a fair and complete sample of the FLLM literature, since no search protocol, database choices, inclusion criteria, or date range are reported.

Editorial extensions

If this is right

  • If FLLM feasibility is as mature as the survey says, new systems research should stop re-deriving parameter-efficient fine-tuning from scratch and instead benchmark against existing FedPEFT baselines.
  • If robustness is dominated by resource-heterogeneity work, then data and task heterogeneity are the highest-leverage unsolved problems, with the cited adapter- and LoRA-based methods serving as early entries rather than settled solutions.
  • If security research is sparse and backdoor-centric, then defenses such as robust aggregation, frequency-domain detection, and distribution-divergence checks are not yet a complete answer, and deployments should assume a residual attack surface.
  • If the future directions are few-shot learning, machine unlearning, and IP protection, then FLLM's next phase will be judged by data efficiency, forgetfulness, and ownership verification rather than by raw accuracy alone.
  • If the integration inherits risks from both FL and LLMs, then privacy must be argued per attack rather than assumed from the federated setting, since gradient and embedding leakage can reconstruct text.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper does not draw this consequence, but its own density counts imply a testable prediction: publication volume in the data-heterogeneity and security cells should grow faster than volume in the feasibility cell over the next few years, and a citation analysis could check that.
  • The survey's separation of robustness from security invites a cross-cutting reading that is left implicit: heterogeneity methods that split the model into per-client low-rank modules also change the attack surface, so aggregation of different ranks or adapters may be harder to poison yet easier to fingerprint.
  • Long-tailed data leakage, treated here as a privacy risk, could equally be studied as a robustness risk: a model that memorizes rare client data is both leaking and failing to generalize, so privacy and robustness defenses may converge on the same mechanisms of regularization, noise, or selective forgetting.
  • If membership inference is genuinely weak for large LLMs because training uses massive data and few epochs, then privacy scrutiny for FLLM may shift toward reconstruction and jailbreaking attacks; that is an inference about where limited defense effort should go, not a claim the paper makes.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. This manuscript is a survey of federated large language models (FLLM). It organizes the literature into four perspectives: feasibility (fine-tuning methods, including full-parameter, PEFT, prompt tuning, and other techniques), robustness (resource, data, and task heterogeneity), security (privacy leakage, poisoning, backdoor attacks, and defenses), and future directions (few-shot learning, unlearning, and IP protection). The paper claims to be an exhaustive survey of recent FLLM research, and its main thesis is that feasibility has received the most attention while robustness and security remain underdeveloped.

Significance. If the reference base were reliable, this survey would provide a useful structured entry point to a fast-growing field. The four-perspective taxonomy is sensible and the paper covers a broad set of recent methods, including many 2023–2024 papers. The authors also make a defensible high-level observation that heterogeneity and security issues are less thoroughly studied than feasibility. The paper does not present new algorithms or experiments, but surveys can be valuable contributions when they organize and assess the literature faithfully. That value is currently compromised by citation inaccuracies and the absence of a documented selection methodology, as detailed below.

major comments (3)
  1. [Section 4.1.2] The text states: 'Mu et al. [157] studied a gradient-based reconstruction attack algorithm ... they proposed an algorithm called deep leakage from gradient (DLG)'. However, reference [157] is Zhu, Liu, and Han, 'Deep Leakage from Gradients', NeurIPS 2019. The DLG algorithm is authored by Zhu et al., not 'Mu et al.' This is not a cosmetic typo: it misattributes a foundational attack in the core security discussion of the survey, and it indicates that the reference list has not been systematically verified against the cited content.
  2. [Table 2 and Section 5.1] The same paper, Cai et al., 'Federated Few-Shot Learning for Mobile NLP' (MobiCom 2023), is cited as [13] in Table 2 and as [14] in Section 5.1. This duplication inflates the apparent number of distinct FLLM contributions and confuses the taxonomy, since the reader cannot tell whether FeS is being listed twice or two different works are being referenced. The reference list must be de-duplicated and all such occurrences reconciled.
  3. [Section 1 and Abstract] The abstract promises 'an exhaustive survey' and Section 1 states that 'our work surveys the latest FLLM research,' but the manuscript does not report any literature search protocol, database choices, inclusion criteria, or date range. Without this information, the representativeness of the cited literature cannot be assessed, and the paper's central gap analysis (that robustness and security are underdeveloped relative to feasibility) may reflect the authors' selection rather than the actual state of the field. The authors should add a methodology subsection describing how the literature was collected and filtered.
minor comments (4)
  1. [Figure 1] The caption contains a typo: 'Full-paramete' should be 'Full-parameter'.
  2. [Table 1] The symbol '✔–' is used in the comparison table but is not defined in the table footnote; please define it explicitly to avoid ambiguity with '✓'.
  3. [Section 3.3] The sentence 'This generalization ability enables the model to perform better when facing new tasks' is a reasonable claim but no citation is provided; adding a reference to multi-task learning literature would strengthen the statement.
  4. [Section 4.1.2] The description of the 'analysis-based attacks' category cites [82] and [155], but the text says these methods 'solve a system of linear equations' without elaborating on the specific mechanism; a brief explanation or example would improve readability.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity found: the paper is a literature survey with no derivation chain, fitted parameters, or self-citation used to force its conclusions.

full rationale

This manuscript is a survey of federated large language models (FLLM). It does not derive a formal result, fit parameters to data, or make a predictive claim from an input model. Its central content is a taxonomy of existing FLLM feasibility, robustness, security, and future-direction papers, organized around the authors' chosen four-dimension framework. Because the taxonomy is a synthesis of external literature rather than a derived consequence of an assumed premise, there is no step in which an output is equivalent to an input by construction. The reader's identified citation concerns, such as attributing DLG to 'Mu et al.' and duplicating the FeS reference as [13] and [14], are accuracy and completeness issues in the survey's reference base; they do not constitute circular reasoning, since the survey's claims are not derived from those references in a self-referential way. No self-citation chain is load-bearing: the authors do not invoke their own prior uniqueness theorems or ansatze to justify the survey's organization. The absence of a reported literature search protocol weakens the survey's reliability but is not a circularity defect under the specified criteria. Accordingly, the appropriate finding is no significant circularity, with score 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The survey introduces no free parameters or invented entities. Its load-bearing assumptions are about literature coverage, the validity of its taxonomy, and the accuracy of its citations.

assumptions (3)
  • domain assumption The selected papers constitute a comprehensive and representative sample of FLLM research.
    The paper claims to be an exhaustive survey of the latest work but provides no search methodology or inclusion criteria, so coverage is taken as an assumption.
  • ad hoc to paper The four-perspective taxonomy (feasibility, robustness, security, future directions) is a valid organizing structure for the field.
    This framing is the authors' own lens; if it omits relevant dimensions, the survey's structure would misrepresent the field.
  • domain assumption The survey's descriptions of cited methods are accurate.
    The paper does not reproduce experiments; it depends on the authors' summaries, and some attributions are inconsistent, e.g., DLG credited to 'Mu et al.' in Section 4.1.2 while reference [157] is Zhu et al.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Federated Large Language Models: Feasibility, Robustness, Security and Future Directions." pith.science (2026). https://pith.science/paper/3TDYIH3J

@misc{pith2026250508830,
  author       = {Pith},
  title        = {Pith review of: Federated Large Language Models: Feasibility, Robustness, Security and Future Directions},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/3TDYIH3J}},
  note         = {Machine review of arXiv:2505.08830}
}
read the original abstract

The integration of Large Language Models (LLMs) and Federated Learning (FL) presents a promising solution for joint training on distributed data while preserving privacy and addressing data silo issues. However, this emerging field, known as Federated Large Language Models (FLLM), faces significant challenges, including communication and computation overheads, heterogeneity, privacy and security concerns. Current research has primarily focused on the feasibility of FLLM, but future trends are expected to emphasize enhancing system robustness and security. This paper provides a comprehensive review of the latest advancements in FLLM, examining challenges from four critical perspectives: feasibility, robustness, security, and future directions. We present an exhaustive survey of existing studies on FLLM feasibility, introduce methods to enhance robustness in the face of resource, data, and task heterogeneity, and analyze novel risks associated with this integration, including privacy threats and security challenges. We also review the latest developments in defense mechanisms and explore promising future research directions, such as few-shot learning, machine unlearning, and IP protection. This survey highlights the pressing need for further research to enhance system robustness and security while addressing the unique challenges posed by the integration of FL and LLM.

Figures

Figures reproduced from arXiv: 2505.08830 by the authors.

Figure 1
Figure 1. The framework of this survey. Darker circles indicate a higher number of related studies. [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. The fine-tuning process of full-parameter fine-tuning, PEFT (including partial-parameter fine-tuning, LoRA, Adapter) and [PITH_FULL_IMAGE:figures/full_fig_p006_2.png] view at source ↗
Figure 3
Figure 3. The process of Adapter-based Fine-tuning and LoRA-based Fine-tuning. [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figures from the paper (4 more)
Figure 4
Figure 4. Figure 4: The framework and workflow of PROMPTFL from [ [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: FlexLoRA workflow from [6]. The server aggregates the full-size LoRA after multiplication, not the individual matrices A and B. The global full-size LoRA is then decomposed into smaller matrices of varying ranks via SVD and allocated sequentially based on client resour…
Figure 6
Figure 6. Figure 6: Privacy and security threats faced by FLLM system. Honest-but-curious server steals client privacy through MIA and DRA. [PITH_FULL_IMAGE:figures/full_fig_p016_6.png]
Figure 7
Figure 7. Figure 7: FedIT-U2S workflow from [130]. FedIT-U2S employs a retrieval-based example selection technique to automatically select the most relevant examples for each client’s unstructured data from an example pool provided by the server. These examples are then combined with the …

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SeFoRA: Sketch-Aggregated Federated Low-Rank Adaptation with Heterogeneous Client Ranks

    cs.LG 2026-08 conditional novelty 6.0 of 10

    A federated fine-tuning method that aggregates clients' sketched LoRA updates linearly, removing the bilinear mismatch and handling heterogeneous ranks without full-model computation.

Reference graph

Works this paper leans on

162 extracted references · 34 canonical work pages · cited by 1 Pith paper

  1. [157]

    Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems 32 (2019)

  2. [13]

    Dongqi Cai, Shangguang Wang, Yaozong Wu, Felix Xiaozhu Lin, and Mengwei Xu. 2023. Federated Few-Shot Learning for Mobile NLP. In 29th Annual International Conference on Mobile Computing and Networking, MobiCom 2023

  3. [14]

    Dongqi Cai, Shangguang Wang, Yaozong Wu, Felix Xiaozhu Lin, and Mengwei Xu. 2023. Federated few-shot learning for mobile nlp. InProceedings of the 29th Annual International Conference on Mobile Computing and Networking . 1–17

  4. [23]

    Alexander V Eriksen, Sören Möller, and Jesper Ryg. 2024. Use of GPT-4 to diagnose complex clinical cases. AIp2300031 pages

  5. [1]

    Samiul Alam, Luyang Liu, Ming Yan, and Mi Zhang. 2022. Fedrolex: Model-heterogeneous federated learning with rolling sub-model extraction. Advances in neural information processing systems 35 (2022), 29677–29690

  6. [2]

    Ebtisaam Alharbi, Leandro Soriano Marcolino, Qiang Ni, and Antonios Gouglidis. 2025. Robust Knowledge Distillation in Federated Learning: Counteracting Backdoor Attacks. CoRR abs/2502.00587 (2025). doi:10.48550/ARXIV.2502.00587 arXiv:2502.00587

  7. [3]

    Adversarially Guided Stateful Defense Against Backdoor Attacks in Federated Deep Learning

    Hassan Ali, Surya Nepal, Salil S. Kanhere, and Sanjay K. Jha. 2024. Adversarially Guided Stateful Defense Against Backdoor Attacks in Federated Deep Learning. CoRR abs/2410.11205 (2024). doi:10.48550/ARXIV.2410.11205 arXiv:2410.11205

  8. [4]

    Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International conference on artificial intelligence and statistics . PMLR, 2938–2948

Show all 162 references
  1. [5]

    Guangji Bai, Yijiang Li, Zilinghan Li, Liang Zhao, and Kibaek Kim. 2024. FedSpaLLM: Federated Pruning of Large Language Models. CoRR abs/2410.14852 (2024). doi:10.48550/ARXIV.2410.14852 arXiv:2410.14852

  2. [6]

    Jiamu Bai, Daoyuan Chen, Bingchen Qian, Liuyi Yao, and Yaliang Li. 2024. Federated fine-tuning of large language models under heterogeneous tasks and client resources. In The Thirty-eighth Annual Conference on Neural Information Processing Systems

  3. [7]

    Li Bai, Haibo Hu, Qingqing Ye, Haoyang Li, Leixia Wang, and Jianliang Xu. 2024. Membership Inference Attacks and Defenses in Federated Learning: A Survey. Comput. Surveys 57, 4 (2024), 1–35

  4. [8]

    Santanu Basak and Kakali Chatterjee. 2025. DPAD: Data Poisoning Attack Defense Mechanism for federated learning-based system. Computers and Electrical Engineering 121 (2025), 109893

  5. [9]

    Hajira Batool, Adeel Anjum, Abid Khan, Stefano Izzo, Carlo Mazzocca, and Gwanggil Jeon. 2024. A secure and privacy preserved infrastructure for VANETs based on federated learning with local differential privacy. Information Sciences 652 (2024), 119717

  6. [10]

    Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In International conference on machine learning . PMLR, 634–643

  7. [11]

    Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013. Evasion attacks against machine learning at test time. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intellige...

  8. [12]

    Rishi Bommasani, Drew A Hudson, Ehsan Adeli, Russ Altman, Simran Arora, Sydney von Arx, Michael S Bernstein, Jeannette Bohg, Antoine Bosselut, Emma Brunskill, et al . 2021. On the opportunities and risks of foundation models. CoRR abs/2108.07258 (2021). arXiv:2108.07258 https:...

  9. [15]

    Dongqi Cai, Yaozong Wu, Shangguang Wang, Felix Xiaozhu Lin, and Mengwei Xu. 2022. Fedadapter: Efficient federated learning for modern nlp. arXiv preprint arXiv:2205.10162 (2022)

  10. [16]

    Dongqi Cai, Yaozong Wu, Shangguang Wang, Felix Xiaozhu Lin, and Mengwei Xu. 2023. Efficient federated learning for modern nlp. InProceedings of the 29th Annual International Conference on Mobile Computing and Networking . 1–16

  11. [17]

    Dongqi Cai, Yaozong Wu, Haitao Yuan, Shangguang Wang, Felix Xiaozhu Lin, and Mengwei Xu. 2023. Towards practical few-shot federated nlp. In Proceedings of the 3rd Workshop on Machine Learning and Systems . 42–48

  12. [18]

    Chaochao Chen, Xiaohua Feng, Jun Zhou, Jianwei Yin, and Xiaolin Zheng. 2023. Federated Large Language Model: A Position Paper. CoRR abs/2307.08925 (2023). doi:10.48550/ARXIV.2307.08925 arXiv:2307.08925

  13. [19]

    Haokun Chen, Yao Zhang, Denis Krompass, Jindong Gu, and Volker Tresp. 2024. Feddat: An approach for foundation model finetuning in multi-modal heterogeneous federated learning. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 38. 11285–11293

  14. [20]

    Yi-Qiang Chen, Teng Zhang, Xin-Long Jiang, Qian Chen, Chen-Long Gao, and Wu-Liang Huang. 2024. Fedbone: Towards large-scale federated multi-task learning. Journal of Computer Science and Technology 39, 5 (2024), 1040–1057

  15. [21]

    Yae Jee Cho, Luyang Liu, Zheng Xu, Aldi Fahrezi, and Gauri Joshi. 2024. Heterogeneous lora for federated fine-tuning of on-device foundation models. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing . 12903–12913

  16. [22]

    Michael Duan, Anshuman Suri, Niloofar Mireshghallah, Sewon Min, Weijia Shi, Luke Zettlemoyer, Yulia Tsvetkov, Yejin Choi, David Evans, and Hannaneh Hajishirzi. 2024. Do Membership Inference Attacks Work on Large Language Models? CoRR abs/2402.07841 (2024). doi:10.48550/ARXIV. ...

  17. [24]

    Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to{Byzantine-Robust} federated learning. In 29th USENIX security symposium (USENIX Security 20) . 1605–1622

  18. [25]

    Zihan Fang, Zheng Lin, Zhe Chen, Xianhao Chen, Yue Gao, and Yuguang Fang. 2024. Automated Federated Pipeline for Parameter-Efficient Fine-Tuning of Large Language Models. CoRR abs/2404.06448 (2024). doi:10.48550/ARXIV.2404.06448 arXiv:2404.06448

  19. [26]

    Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum, and Tom Goldstein

    Liam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum, and Tom Goldstein. 2022. Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models. In The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April...

  20. [27]

    Fowl, Jonas Geiping, Steven Reich, Yuxin Wen, Wojciech Czaja, Micah Goldblum, and Tom Goldstein

    Liam H. Fowl, Jonas Geiping, Steven Reich, Yuxin Wen, Wojciech Czaja, Micah Goldblum, and Tom Goldstein. 2023. Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models. In The Eleventh International Conference on Learning Representations, IC...

  21. [28]

    Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) . 301–316

  22. [29]

    Tao Guo, Song Guo, Junxiao Wang, Xueyang Tang, and Wenchao Xu. 2023. Promptfl: Let federated participants cooperatively learn prompts instead of models-federated learning in age of foundation model. IEEE Transactions on Mobile Computing (2023)

  23. [30]

    Umang Gupta, Dimitris Stripelis, Pradeep K Lam, Paul Thompson, Jose Luis Ambite, and Greg Ver Steeg. 2021. Membership inference attacks on deep regression models for neuroimaging. In Medical Imaging with Deep Learning . PMLR, 228–251

  24. [31]

    Mengde Han, Tianqing Zhu, and Wanlei Zhou. 2024. Fair Federated Learning with Opposite GAN. Knowledge-Based Systems (2024), 111420. Issue No.C

  25. [32]

    Shanshan Han, Baturalp Buyukates, Zijian Hu, Han Jin, Weizhao Jin, Lichao Sun, Xiaoyang Wang, Wenxuan Wu, Chulin Xie, Yuhang Yao, et al. 2024. Fedsecurity: A benchmark for attacks and defenses in federated learning and federated llms. In Proceedings of the 30th ACM SIGKDD Conf...

  26. [33]

    Neil Houlsby, Andrei Giurgiu, Stanislaw Jastrzebski, Bruna Morrone, Quentin De Laroussilhe, Andrea Gesmundo, Mona Attariyan, and Sylvain Gelly. 2019. Parameter-efficient transfer learning for NLP. In International conference on machine learning . PMLR, 2790–2799

  27. [34]

    Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen

    Edward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2022. LoRA: Low-Rank Adaptation of Large Language Models. In The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 20...

  28. [35]

    Jiahui Hu, Dan Wang, Zhibo Wang, Xiaoyi Pang, Huiyu Xu, Ju Ren, and Kui Ren. 2024. Federated Large Language Model: Solutions, Challenges and Future Directions. IEEE Wireless Communications (2024)

  29. [36]

    Teodor Ivănus,că and Cosmin-Iulian Irimia. 2024. The Impact of Prompting Techniques on the Security of the LLMs and the Systems to Which They Belong. Applied Sciences (2076-3417) 14, 19 (2024)

  30. [37]

    Ruofan Jia, Weiying Xie, Jie Lei, Haonan Qin, Jitao Ma, and Leyuan Fang. 2024. Towards Efficient Model-Heterogeneity Federated Learning for Large Models. CoRR abs/2411.16796 (2024). doi:10.48550/ARXIV.2411.16796 arXiv:2411.16796

  31. [38]

    Feibo Jiang, Li Dong, Siwei Tu, Yubo Peng, Kezhi Wang, Kun Yang, Cunhua Pan, and Dusit Niyato. 2024. Personalized Wireless Federated Learning for Large Language Models. CoRR abs/2404.13238 (2024). doi:10.48550/ARXIV.2404.13238 arXiv:2404.13238

  32. [39]

    Jingang Jiang, Haiqi Jiang, Yuhan Ma, Xiangyang Liu, and Chenyou Fan. 2024. Low-parameter federated learning with large language models. In International Conference on Web Information Systems and Applications . Springer, 319–330

  33. [40]

    Shuyu Jiang, Xingshu Chen, Kaiyu Xu, Liangguo Chen, Hao Ren, and Rui Tang. 2025. Decomposition, Synthesis and Attack: A Multi-Instruction Fusion Method for Jailbreaking LLMs. IEEE Internet of Things Journal (2025)

  34. [41]

    Gihun Lee, Minchan Jeong, Yujin Kim, Hojung Jung, Jaehoon Oh, SangMook Kim, and Se-Young Yun. 2024. BAPO: Base-Anchored Preference Optimization for Overcoming Forgetting in Large Language Models Personalization. In Findings of the Association for Computational Linguistics: EMN...

  35. [42]

    Brian Lester, Rami Al-Rfou, and Noah Constant. 2021. The Power of Scale for Parameter-Efficient Prompt Tuning. In Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, EMNLP 2021, Virtual Event / Punta Cana, Dominican Republic, 7-11 November, ...

  36. [43]

    Bowen Li, Lixin Fan, Hanlin Gu, Jie Li, and Qiang Yang. 2022. FedIPR: Ownership verification for federated deep neural network models. IEEE Transactions on Pattern Analysis and Machine Intelligence 45, 4 (2022), 4521–4536

  37. [44]

    Hongyu Li, Liang Ding, Meng Fang, and Dacheng Tao. 2024. Revisiting Catastrophic Forgetting in Large Language Model Tuning. In Findings of the Association for Computational Linguistics: EMNLP 2024, Miami, Florida, USA, November 12-16, 2024 , Yaser Al-Onaizan, Mohit Bansal, and...

  38. [45]

    Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2023. Effective passive membership inference attacks in federated learning against overparameterized models. In The Eleventh International Conference on Learning Representations

  39. [46]

    Junnan Li, Ramprasaath Selvaraju, Akhilesh Gotmare, Shafiq Joty, Caiming Xiong, and Steven Chu Hong Hoi. 2021. Align before fuse: Vision and language representation learning with momentum distillation. Advances in neural information processing systems 34 (2021), 9694–9705

  40. [47]

    Qinbin Li, Yiqun Diao, Quan Chen, and Bingsheng He. 2022. Federated learning on non-iid data silos: An experimental study. In 2022 IEEE 38th international conference on data engineering (ICDE) . IEEE, 965–978

  41. [48]

    Shenghui Li, Edith C-H Ngai, and Thiemo Voigt. 2023. An experimental study of byzantine-robust aggregation schemes in federated learning. IEEE Transactions on Big Data (2023)

  42. [49]

    Shenghui Li, Edith C. H. Ngai, Fanghua Ye, and Thiemo Voigt. 2024. PEFT-as-an-Attack! Jailbreaking Language Models during Federated Parameter-Efficient Fine-Tuning. CoRR abs/2411.19335 (2024). doi:10.48550/ARXIV.2411.19335 arXiv:2411.19335 Manuscript submitted to ACM Federated...

  43. [50]

    Shenghui Li, Fanghua Ye, Meng Fang, Jiaxu Zhao, Yun-Hin Chan, Edith C. H. Ngai, and Thiemo Voigt. 2024. Synergizing Foundation Models and Federated Learning: A Survey. CoRR abs/2406.12844 (2024). doi:10.48550/ARXIV.2406.12844 arXiv:2406.12844

  44. [51]

    Xingyu Li, Lu Peng, Yu-Ping Wang, and Weihua Zhang. 2025. Open challenges and opportunities in federated foundation models towards biomedical healthcare. BioData Min. 18, 1 (2025). doi:10.1186/S13040-024-00414-9

  45. [52]

    Xi Li and Jiaqi Wang. 2024. Position Paper: Assessing Robustness, Privacy, and Fairness in Federated Learning Integrated with Foundation Models. CoRR abs/2402.01857 (2024). doi:10.48550/ARXIV.2402.01857 arXiv:2402.01857

  46. [53]

    Xi Li, Songhe Wang, Chen Wu, Hao Zhou, and Jiaqi Wang. 2023. Backdoor Threats from Compromised Foundation Models to Federated Learning. CoRR abs/2311.00144 (2023). doi:10.48550/ARXIV.2311.00144 arXiv:2311.00144

  47. [54]

    Xi Li, Chen Wu, and Jiaqi Wang. 2024. Unveiling backdoor risks brought by foundation models in heterogeneous federated learning. In Pacific-Asia Conference on Knowledge Discovery and Data Mining . Springer, 168–181

  48. [55]

    Zhiwei Li and Guodong Long. 2024. Navigating the Future of Federated Recommendation Systems with Foundation Models. CoRR abs/2406.00004 (2024). doi:10.48550/ARXIV.2406.00004 arXiv:2406.00004

  49. [56]

    Yuying Liao, Rong Jiang, and Bin Zhou. 2024. Dynamic Black-Box Model Watermarking for Heterogeneous Federated Learning. Electronics 13, 21 (2024), 4306

  50. [57]

    Zheng Lin, Xuanjie Hu, Yuxin Zhang, Zhe Chen, Zihan Fang, Xianhao Chen, Ang Li, Praneeth Vepakomma, and Yue Gao. 2024. SplitLoRA: A Split Parameter-Efficient Fine-Tuning Framework for Large Language Models. CoRR abs/2407.00952 (2024). doi:10.48550/ARXIV.2407.00952 arXiv:2407.00952

  51. [58]

    Zhenqing Ling, Daoyuan Chen, Liuyi Yao, Yaliang Li, and Ying Shen. 2024. On the convergence of zeroth-order federated tuning for large language models. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 1827–1838

  52. [59]

    Aiwei Liu, Leyi Pan, Yijian Lu, Jingjing Li, Xuming Hu, Xi Zhang, Lijie Wen, Irwin King, Hui Xiong, and Philip Yu. 2024. A survey of text watermarking in the era of large language models. Comput. Surveys 57, 2 (2024), 1–36

  53. [60]

    Bowen Liu, Boao Xiao, Xutong Jiang, Siyuan Cen, Xin He, and Wanchun Dou. 2023. Adversarial Attacks on Large Language Model-Based System and Mitigating Strategies: A Case Study on ChatGPT. Security & Communication Networks (2023)

  54. [61]

    Xiao Liu, Kaixuan Ji, Yicheng Fu, Zhengxiao Du, Zhilin Yang, and Jie Tang. 2021. P-Tuning v2: Prompt Tuning Can Be Comparable to Fine-tuning Universally Across Scales and Tasks. CoRR abs/2110.07602 (2021). arXiv:2110.07602 https://arxiv.org/abs/2110.07602

  55. [62]

    Yang Liu, Mingyuan Fan, Cen Chen, Ximeng Liu, Zhuo Ma, Li Wang, and Jianfeng Ma. 2022. Backdoor defense with machine unlearning. In IEEE INFOCOM 2022-IEEE conference on computer communications . IEEE, 280–289

  56. [63]

    Yuxi Liu, Guibo Luo, and Yuesheng Zhu. 2024. FedFMS: Exploring Federated Foundation Models for Medical Image Segmentation. In International Conference on Medical Image Computing and Computer-Assisted Intervention . Springer, 283–293

  57. [64]

    Yi Liu, Lei Xu, Xingliang Yuan, Cong Wang, and Bo Li. 2022. The right to be forgotten in federated learning: An efficient realization with rapid retraining. In IEEE INFOCOM 2022-IEEE conference on computer communications . IEEE, 1749–1758

  58. [65]

    Jiahao Lu, Xi Sheryl Zhang, Tianli Zhao, Xiangyu He, and Jian Cheng. 2022. April: Finding the achilles’ heel on privacy for vision transformers. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 10051–10060

  59. [66]

    Wang Lu, Hao Yu, Jindong Wang, Damien Teney, Haohan Wang, Yiqiang Chen, Qiang Yang, Xing Xie, and Xiangyang Ji. 2023. ZooPFL: Exploring Black-box Foundation Models for Personalized Federated Learning. CoRR abs/2310.05143 (2023). doi:10.48550/ARXIV.2310.05143 arXiv:2310.05143

  60. [67]

    Xiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu, Yongsheng Zhu, Guangquan Xu, Jiqiang Liu, and Xiangliang Zhang. 2024. Lurking in the shadows: Unveiling stealthy backdoor attacks against personalized federated learning. In 33rd USENIX Security Symposium (USENIX Security 24) . 4157–4174

  61. [68]

    Xiaodong Ma, Jia Zhu, Zhihao Lin, Shanxuan Chen, and Yangjie Qin. 2022. A state-of-the-art survey on solving non-iid data in federated learning. Future Generation Computer Systems 135 (2022), 244–258

  62. [69]

    Zihan Ma and Tianchong Gao. 2024. Federated learning backdoor attack detection with persistence diagram. Computers & Security 136 (2024), 103557

  63. [70]

    Zhuo Ma, Yang Liu, Ximeng Liu, Jian Liu, Jianfeng Ma, and Kui Ren. 2022. Learn to forget: Machine unlearning via neuron masking. IEEE Transactions on Dependable and Secure Computing 20, 4 (2022), 3194–3207

  64. [71]

    Shubham Malaviya, Manish Shukla, and Sachin Lodha. 2023. Reducing communication overhead in federated learning for pre-trained language models using parameter-efficient finetuning. In Conference on Lifelong Learning Agents . PMLR, 456–469

  65. [72]

    Yuren Mao, Yuhang Ge, Yijiang Fan, Wenyi Xu, Yu Mi, Zhonghao Hu, and Yunjun Gao. 2025. A survey on lora of large language models. Frontiers of Computer Science 19, 7 (2025), 197605

  66. [73]

    Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273–1282

  67. [74]

    Hanzi Mei, Dongqi Cai, Ao Zhou, Shangguang Wang, and Mengwei Xu. 2024. FedMoE: Personalized Federated Learning via Heterogeneous Mixture of Experts. CoRR abs/2408.11304 (2024). doi:10.48550/ARXIV.2408.11304 arXiv:2408.11304

  68. [75]

    Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In 2019 IEEE symposium on security and privacy (SP) . IEEE, 691–706

  69. [76]

    Matias Mendieta, Taojiannan Yang, Pu Wang, Minwoo Lee, Zhengming Ding, and Chen Chen. 2022. Local learning matters: Rethinking data heterogeneity in federated learning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 8397–8406. Manuscript...

  70. [77]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP) . IEEE, 739–753

  71. [78]

    Truc D. T. Nguyen, Phung Lai, Khang Tran, NhatHai Phan, and My T. Thai. 2023. Active Membership Inference Attack under Local Differential Privacy in Federated Learning. InInternational Conference on Artificial Intelligence and Statistics, 25-27 April 2023, Palau de Congressos,...

  72. [79]

    Kunjal Panchal, Nisarg Parikh, Sunav Choudhary, Lijun Zhang, Yuriy Brun, and Hui Guan. 2024. Thinking Forward: Memory-Efficient Federated Finetuning of Language Models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing ...

  73. [80]

    Dimitrov, Maximilian Baader, Mark Niklas Müller, and Martin T

    Ivo Petrov, Dimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, and Martin T. Vechev. 2024. DAGER: Exact Gradient Inversion for Large Language Models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 20...

  74. [81]

    Jonas Pfeiffer, Aishwarya Kamath, Andreas Rücklé, Kyunghyun Cho, and Iryna Gurevych. 2021. AdapterFusion: Non-Destructive Task Composition for Transfer Learning. In Proceedings of the 16th Conference of the European Chapter of the Association for Computational Linguistics: Mai...

  75. [82]

    Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, and Shiho Moriai. 2017. Privacy-preserving deep learning: Revisited and enhanced. In Applications and Techniques in Information Security: 8th International Conference, ATIS 2017, Auckland, New Zealand, July 6–7, 2017,...

  76. [83]

    Georg Pichler, Marco Romanelli, Leonardo Rey Vega, and Pablo Piantanida. 2023. Perfectly accurate membership inference by a dishonest central server in federated learning. IEEE Transactions on Dependable and Secure Computing (2023)

  77. [84]

    Siqi Ping, Yuzhu Mao, Yang Liu, Xiao-Ping Zhang, and Wenbo Ding. 2024. FL-TAC: Enhanced Fine-Tuning in Federated Learning via Low-Rank, Task-Specific Adapter Clustering. CoRR abs/2404.15384 (2024). doi:10.48550/ARXIV.2404.15384 arXiv:2404.15384

  78. [85]

    Fung, Hailong Yang, and Depei Qian

    Jiaxing Qi, Zhongzhi Luan, Shaohan Huang, Carol J. Fung, Hailong Yang, and Depei Qian. 2024. FDLoRA: Personalized Federated Learning of Large Language Model via Dual LoRA Tuning. CoRR abs/2406.07925 (2024). doi:10.48550/ARXIV.2406.07925 arXiv:2406.07925

  79. [86]

    Zhen Qin, Daoyuan Chen, Bingchen Qian, Bolin Ding, Yaliang Li, and Shuiguang Deng. 2024. Federated Full-Parameter Tuning of Billion-Sized Language Models with Communication Cost under 18 Kilobytes. In Forty-first International Conference on Machine Learning, ICML 2024, Vienna,...

  80. [87]

    Chen Qiu, Xingyu Li, Chaithanya Kumar Mummadi, Madan Ravi Ganesh, Zhenzhen Li, Lu Peng, and Wan-Yi Lin. 2023. Text-driven Prompt Generation for Vision-Language Models in Federated Learning. CoRR abs/2310.06123 (2023). doi:10.48550/ARXIV.2310.06123 arXiv:2310.06123

  81. [88]

    Chen Qiu, Xingyu Li, Chaithanya Kumar Mummadi, Madan Ravi Ganesh, Zhenzhen Li, Lu Peng, and Wan-Yi Lin. 2024. Federated text-driven prompt generation for vision-language models. In The Twelfth International Conference on Learning Representations

  82. [89]

    Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al. 2021. Learning transferable visual models from natural language supervision. In International conference on machine learni...

  83. [90]

    Rafi Ur Rashid, Vishnu Asutosh Dasu, Kang Gu, Najrin Sultana, and Shagufta Mehnaz

    Md. Rafi Ur Rashid, Vishnu Asutosh Dasu, Kang Gu, Najrin Sultana, and Shagufta Mehnaz. 2023. FLTrojan: Privacy Leakage Attacks against Federated Language Models Through Selective Weight Tampering. CoRR abs/2310.16152 (2023). doi:10.48550/ARXIV.2310.16152 arXiv:2310.16152

  84. [91]

    Chao Ren, Han Yu, Hongyi Peng, Xiaoli Tang, Anran Li, Yulan Gao, Alysa Ziying Tan, Bo Zhao, Xiaoxiao Li, Zengxiang Li, and Qiang Yang. 2024. Advances and Open Challenges in Federated Learning with Foundation Models. CoRR abs/2404.15381 (2024). doi:10.48550/ARXIV.2404.15381 arX...

  85. [92]

    Yanli Ren, Mingqi Hu, Zhe Yang, Guorui Feng, and Xinpeng Zhang. 2024. BPFL: Blockchain-based privacy-preserving federated learning against poisoning attack. Information Sciences 665 (2024), 120377

  86. [93]

    Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems 31 (2018)

  87. [94]

    Virat Shejwalkar and Amir Houmansadr. 2021. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS

  88. [95]

    Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, and Daniel Ramage. 2022. Back to the drawing board: A critical evaluation of poisoning attacks on production federated learning. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 1354–1371

  89. [96]

    Jiyun Shin, Jinhyun Ahn, Honggu Kang, and Joonhyuk Kang. 2023. FedSplitX: Federated Split Learning for Computationally-Constrained Heterogeneous Clients. CoRR abs/2310.14579 (2023). doi:10.48550/ARXIV.2310.14579 arXiv:2310.14579

  90. [97]

    Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 3–18. Manuscript submitted to ACM Federated Large Language Models: Feasibility, Ro...

  91. [98]

    Abhishek Singh, Praneeth Vepakomma, Otkrist Gupta, and Ramesh Raskar. 2019. Detailed comparison of communication efficiency of split learning and federated learning. CoRR abs/1909.09145 (2019). arXiv:1909.09145 http://arxiv.org/abs/1909.09145

  92. [99]

    Ningxin Su, Chenghao Hu, Baochun Li, and Bo Li. 2024. TITANIC: Towards production federated learning with large language models. In IEEE INFOCOM 2024-IEEE Conference on Computer Communications . IEEE, 611–620

  93. [100]

    Ningxin Su and Baochun Li. 2023. Asynchronous federated unlearning. In IEEE INFOCOM 2023-IEEE conference on computer communications . IEEE, 1–10

  94. [101]

    Shangchao Su, Bin Li, and Xiangyang Xue. 2025. Fedra: A random allocation strategy for federated tuning to unleash the power of heterogeneous clients. In European Conference on Computer Vision . Springer, 342–358

  95. [102]

    Yang Su, Na Yan, and Yansha Deng. 2024. Federated LLMs Fine-tuned with Adaptive Importance-Aware LoRA. CoRR abs/2411.06581 (2024). doi:10.48550/ARXIV.2411.06581 arXiv:2411.06581

  96. [103]

    Guangyu Sun, Umar Khalid, Matias Mendieta, Taojiannan Yang, Pu Wang, Minwoo Lee, and Chen Chen. 2024. Conquering the Communication Constraints to Enable Large Pre-Trained Models in Federated Learning. arXiv:2210.01708 [cs.LG] https://arxiv.org/abs/2210.01708

  97. [104]

    Rishub Tamirisa, Chulin Xie, Wenxuan Bao, Andy Zhou, Ron Arel, and Aviv Shamsian. 2024. FedSelect: Personalized Federated Learning with Customized Selection of Parameters for Fine-Tuning. In 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  98. [105]

    Chandra Thapa, Pathum Chamikara Mahawaga Arachchige, Seyit Camtepe, and Lichao Sun. 2022. Splitfed: When federated learning meets split learning. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 36. 8485–8493

  99. [106]

    Yuanyishu Tian, Yao Wan, Lingjuan Lyu, Dezhong Yao, Hai Jin, and Lichao Sun. 2022. FedBERT: When federated learning meets pre-training. ACM Transactions on Intelligent Systems and Technology (TIST) 13, 4 (2022), 1–26

  100. [107]

    Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data poisoning attacks against federated learning systems. In Computer security–ESORICs 2020: 25th European symposium on research in computer security, ESORICs 2020, guildford, UK, September 14–18, 2020, proc...

  101. [108]

    Pablo Villalobos, Anson Ho, Jaime Sevilla, Tamay Besiroglu, Lennart Heim, and Marius Hobbhahn. 2024. Position: Will we run out of data? Limits of LLM scaling based on human-generated data. In Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria,...

  102. [109]

    Minh Vu, Truc Nguyen, My T Thai, et al. 2024. Analysis of Privacy Leakage in Federated Large Language Models. In International Conference on Artificial Intelligence and Statistics. PMLR, 1423–1431

  103. [110]

    Papailiopoulos

    Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris S. Papailiopoulos. 2020. Attack of the Tails: Yes, You Really Can Backdoor Federated Learning. InAdvances in Neural Information Processing Systems 33:...

  104. [111]

    Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papail- iopoulos. 2020. Attack of the tails: Yes, you really can backdoor federated learning. Advances in Neural Information Processing Systems 33 (20...

  105. [112]

    Lin Wang, Zhichao Wang, and Xiaoying Tang. 2024. Save It All: Enabling Full Parameter Tuning for Federated Large Language Models via Cycle Block Gradient Descent. arXiv:2406.11187 [cs.LG] https://arxiv.org/abs/2406.11187

  106. [113]

    Wenxuan Wang, Kuiyi Gao, Zihan Jia, Youliang Yuan, Jen-tse Huang, Qiuzhi Liu, Shuai Wang, Wenxiang Jiao, and Zhaopeng Tu. 2024. Chain-of- Jailbreak Attack for Image Generation Models via Editing Step by Step.CoRR abs/2410.03869 (2024). doi:10.48550/ARXIV.2410.03869 arXiv:2410.03869

  107. [114]

    Herbert Woisetschläger, Alexander Erben, Shiqiang Wang, Ruben Mayer, and Hans-Arno Jacobsen. 2024. A Survey on Efficient Federated Learning Methods for Foundation Model Training. In Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence, IJCA...

  108. [115]

    Chen Wu, Xi Li, and Jiaqi Wang. 2024. Vulnerabilities of Foundation Model Integrated Federated Learning Under Adversarial Threats. CoRR abs/2401.10375 (2024). doi:10.48550/ARXIV.2401.10375 arXiv:2401.10375

  109. [116]

    Feijie Wu, Zitao Li, Yaliang Li, Bolin Ding, and Jing Gao. 2024. Fedbiot: Llm local fine-tuning in federated learning without full model. InProceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 3345–3355

  110. [117]

    Geming Xia, Jian Chen, Chaodong Yu, and Jun Ma. 2023. Poisoning Attacks in Federated Learning: A Survey. IEEE Access (2023), 10708–10722. Issue 2

  111. [118]

    Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations

  112. [119]

    Jie Xu, Karthikeyan Saravanan, Rogier van Dalen, Haaris Mehmood, David Tuckey, and Mete Ozay. 2024. DP-DyLoRA: Fine-Tuning Transformer- Based Models On-Device under Differentially Private Federated Learning using Dynamic Low-Rank Adaptation. CoRR abs/2405.06368 (2024). doi:10....

  113. [120]

    Mengwei Xu, Dongqi Cai, Yaozong Wu, Xiang Li, and Shangguang Wang. 2024. FwdLLM: Efficient federated finetuning of large language models with perturbed inferences. In USENIX ATC

  114. [121]

    Zhao Xu, Fan Liu, and Hao Liu. 2024. Bag of Tricks: Benchmarking of Jailbreak Attacks on LLMs. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, Vancouver, BC, Canada, December 10 - 15, 2024 ...

  115. [122]

    Choquette-Choo, Peter Kairouz, H

    Zheng Xu, Yanxiang Zhang, Galen Andrew, Christopher A. Choquette-Choo, Peter Kairouz, H. Brendan McMahan, Jesse Rosenstock, and Yuanbo Zhang. 2023. Federated Learning of Gboard Language Models with Differential Privacy. In Proceedings of the The 61st Annual Meeting of the Asso...

  116. [123]

    Haomiao Yang, Mengyu Ge, Dongyun Xue, Kunlan Xiang, Hongwei Li, and Rongxing Lu. 2023. Gradient leakage attacks in federated learning: Research frontiers, taxonomy and future directions. IEEE Network (2023)

  117. [124]

    Tien-Ju Yang, Yonghui Xiao, Giovanni Motta, Françoise Beaufays, Rajiv Mathews, and Mingqing Chen. 2023. Online Model Compression for Federated Learning with Large Models. In ICASSP 2023 - 2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) . ...

  118. [125]

    Wenkai Yang, Lei Li, Zhiyuan Zhang, Xuancheng Ren, Xu Sun, and Bin He. 2021. Be Careful about Poisoned Word Embeddings: Exploring the Vulnerability of the Embedding Layers in NLP Models. In Proceedings of the 2021 Conference of the North American Chapter of the Association for...

  119. [126]

    Yiyuan Yang, Guodong Long, Tao Shen, Jing Jiang, and Michael Blumenstein. 2024. Dual-Personalizing Adapter for Federated Foundation Models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, V...

  120. [127]

    Zheng Yang, Ke Gu, and Yiming Zuo. 2024. Byzantine Robust Federated Learning Scheme Based on Backdoor Triggers. Computers Materi- als&Continua (2024), 2813–2831. Issue 5

  121. [128]

    Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024. A survey on large language model (llm) security and privacy: The good, the bad, and the ugly. High-Confidence Computing (2024), 100211

  122. [129]

    Rossi, Ang Li, Lina Yao, Julian J

    Yuhang Yao, Jianyi Zhang, Junda Wu, Chengkai Huang, Yu Xia, Tong Yu, Ruiyi Zhang, Sungchul Kim, Ryan A. Rossi, Ang Li, Lina Yao, Julian J. McAuley, Yiran Chen, and Carlee Joe-Wong. 2024. Federated Large Language Models: Current Progress and Future Directions.CoRR abs/2409.1572...

  123. [130]

    Rui Ye, Rui Ge, Fengting Yuchi, Jingyi Chai, Yanfeng Wang, and Siheng Chen. 2024. Leveraging unstructured text data for federated instruction tuning of large language models. In International Workshop on Trustworthy Federated Learning . Springer, 119–131

  124. [131]

    Liping Yi, Han Yu, Gang Wang, and Xiaoguang Liu. 2023. FedLoRA: Model-Heterogeneous Personalized Federated Learning with LoRA Tuning. CoRR abs/2310.13283 (2023). doi:10.48550/ARXIV.2310.13283 arXiv:2310.13283

  125. [132]

    yiyuan yang, Guodong Long, Tianyi Zhou, Qinghua Lu, Shanshan Ye, and Jing Jiang. 2025. Federated Adapter on Foundation Models: An Out-Of-Distribution Approach. https://openreview.net/forum?id=LcpdPCkZwI

  126. [133]

    KiYoon Yoo and Nojun Kwak. 2022. Backdoor Attacks in Federated Learning by Rare Embeddings and Gradient Ensembling. In Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing, EMNLP 2022, Abu Dhabi, United Arab Emirates, December 7-11, 2022 , Yoa...

  127. [134]

    Pablo Muñoz, and Ali Jannesari

    Sixing Yu, J. Pablo Muñoz, and Ali Jannesari. 2023. Bridging the Gap Between Foundation Models and Heterogeneous Federated Learning. CoRR abs/2310.00247 (2023). doi:10.48550/ARXIV.2310.00247 arXiv:2310.00247

  128. [135]

    Sixing Yu, Juan Pablo Muñoz, and Ali Jannesari. 2024. Federated Foundation Models: Privacy-Preserving and Collaborative Learning for Large Models. In Proceedings of the 2024 Joint International Conference on Computational Linguistics, Language Resources and Evaluation, LREC/CO...

  129. [136]

    Elad Ben Zaken, Yoav Goldberg, and Shauli Ravfogel. 2022. BitFit: Simple Parameter-efficient Fine-tuning for Transformer-based Masked Language- models. In Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers), ACL 2022...

  130. [137]

    Oualid Zari, Chuan Xu, and Giovanni Neglia. 2021. Efficient passive membership inference attack in federated learning. CoRR abs/2111.00430 (2021). arXiv:2111.00430 https://arxiv.org/abs/2111.00430

  131. [138]

    Yuexiang Zhai, Shengbang Tong, Xiao Li, Mu Cai, Qing Qu, Yong Jae Lee, and Yi Ma. 2023. Investigating the Catastrophic Forgetting in Multimodal Large Language Models. CoRR abs/2309.10313 (2023). doi:10.48550/ARXIV.2309.10313 arXiv:2309.10313

  132. [139]

    Chunxu Zhang, Guodong Long, Hongkuan Guo, Xiao Fang, Yang Song, Zhaojie Liu, Guorui Zhou, Zijian Zhang, Yang Liu, and Bo Yang. 2024. Federated Adaptation for Foundation Model-based Recommendations. In Proceedings of the Thirty-Third International Joint Conference on Artificial...

  133. [140]

    Jiale Zhang, Bing Chen, Xiang Cheng, Huynh Thi Thanh Binh, and Shui Yu. 2020. PoisonGAN: Generative poisoning attacks against federated learning in edge computing systems. IEEE Internet of Things Journal 8, 5 (2020), 3310–3322. Manuscript submitted to ACM Federated Large Langu...

  134. [141]

    Jianxin Zhang, Mengda Zhao, Zhenwei Wang, Weijian Su, and Pengfei Wang. 2025. Model Recovery in Federated Unlearning With Restricted Server Data Resources. IEEE Internet of Things Journal (2025)

  135. [142]

    Liwei Zhang, Linghui Li, Xiaoyong Li, Binsi Cai, Yali Gao, Ruobin Dou, and Luying Chen. 2023. Efficient Membership Inference Attacks against Federated Learning via Bias Differences. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defen...

  136. [143]

    Zeling Zhang, Dongqi Cai, Yiran Zhang, Mengwei Xu, Shangguang Wang, and Ao Zhou. 2024. FedRDMA: Communication-Efficient Cross-Silo Federated LLM via Chunked RDMA Transmission. In Proceedings of the 4th Workshop on Machine Learning and Systems, EuroMLSys 2024, Athens, Greece, 2...

  137. [144]

    Zhiyuan Zhang, Deli Chen, Hao Zhou, Fandong Meng, Jie Zhou, and Xu Sun. 2023. Fed-FA: theoretically modeling client data divergence for federated language backdoor defense. Advances in Neural Information Processing Systems 36 (2023), 62006–62031

  138. [145]

    Zhuo Zhang, Xiangjing Hu, Jingyuan Zhang, Yating Zhang, Hui Wang, Lizhen Qu, and Zenglin Xu. 2023. Fedlegal: The first real-world federated learning benchmark for legal nlp. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: L...

  139. [146]

    Zixin Zhang, Fan Qi, and Changsheng Xu. [n. d.]. Enhancing Storage and Computational Efficiency in Federated Multimodal Learning for Large-Scale Models. In Forty-first International Conference on Machine Learning

  140. [147]

    Zhiyuan Zhang, Qi Su, and Xu Sun. 2022. Dim-Krum: Backdoor-Resistant Federated Learning for NLP with Dimension-wise Krum-Based Aggregation. In Findings of the Association for Computational Linguistics: EMNLP 2022, Abu Dhabi, United Arab Emirates, December 7-11, 2022 , Yoav Gol...

  141. [148]

    Zikai Zhang, Jiahao Xu, Ping Liu, and Rui Hu. 2024. Fed-piLot: Optimizing LoRA Assignment for Efficient Federated Foundation Model Fine-Tuning. CoRR abs/2410.10200 (2024). doi:10.48550/ARXIV.2410.10200 arXiv:2410.10200

  142. [149]

    Jujia Zhao, Wenjie Wang, Chen Xu, Zhaochun Ren, See-Kiong Ng, and Tat-Seng Chua. 2024. LLM-based Federated Recommendation. CoRR abs/2402.09959 (2024). doi:10.48550/ARXIV.2402.09959 arXiv:2402.09959

  143. [150]

    Zihao Zhao, Zhenpeng Shi, Yang Liu, and Wenbo Ding. 2023. Inclusive Data Representation in Federated Learning: A Novel Approach Integrating Textual and Visual Prompt. In Adjunct Proceedings of the 2023 ACM International Joint Conference on Pervasive and Ubiquitous Computing & ...

  144. [151]

    Fei Zheng. 2023. Input Reconstruction Attack against Vertical Federated Large Language Models. CoRR abs/2311.07585 (2023). doi:10.48550/ARXIV. 2311.07585 arXiv:2311.07585

  145. [152]

    Jiaying Zheng, Hainan Zhang, Lingxiang Wang, Wangjie Qiu, Hong-Wei Zheng, and Zhi Ming Zheng. 2024. Safely Learning with Private Data: A Federated Learning Framework for Large Language Model. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Proces...

  146. [153]

    Zan Zhou, Changqiao Xu, Bo Wang, Tengfei Li, Sizhe Huang, Shujie Yang, and Su Yao. 2024. SecFFT: Safeguarding Federated Fine-Tuning for Large Vision Language Models against Covert Backdoor Attacks in IoRT Networks. IEEE Internet of Things Journal (2024)

  147. [154]

    Didi Zhu, Zhongyi Sun, Zexi Li, Tao Shen, Ke Yan, Shouhong Ding, Chao Wu, and Kun Kuang. 2024. Model Tailor: Mitigating Catastrophic Forgetting in Multi-modal Large Language Models. In Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 2...

  148. [155]

    Blaschko

    Junyi Zhu and Matthew B. Blaschko. 2021. R-GAP: Recursive Gradient Attack on Privacy. In9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7, 2021 . OpenReview.net. https://openreview.net/forum?id=RSU17UoKfJF

  149. [156]

    Jianhao Zhu, Changze Lv, Xiaohua Wang, Muling Wu, Wenhao Liu, Tianlong Li, Zixuan Ling, Cenyuan Zhang, Xiaoqing Zheng, and Xuanjing Huang. 2024. Promoting Data and Model Privacy in Federated Learning through Quantized LoRA. In Findings of the Association for Computational Ling...

  150. [158]

    Xiangrong Zhu, Guangyao Li, and Wei Hu. 2023. Heterogeneous federated knowledge graph embedding learning and unlearning. In Proceedings of the ACM web conference 2023 . 2444–2454

  151. [159]

    Weiming Zhuang, Chen Chen, and Lingjuan Lyu. 2023. When Foundation Model Meets Federated Learning: Motivations, Challenges, and Future Directions. CoRR abs/2306.15546 (2023). doi:10.48550/ARXIV.2306.15546 arXiv:2306.15546

  152. [160]

    Xuhan Zuo, Minghao Wang, Tianqing Zhu, Lefeng Zhang, Dayong Ye, Shui Yu, and Wanlei Zhou. 2024. Federated TrustChain: Blockchain-Enhanced LLM Training and Unlearning. CoRR abs/2406.04076 (2024). doi:10.48550/ARXIV.2406.04076 arXiv:2406.04076 Received 20 February 2007; revised ...

  153. [2022]

    https://openreview.net/forum?id=fwzUgo0FM9v

    OpenReview.net. https://openreview.net/forum?id=fwzUgo0FM9v

  154. [2024]

    https://openreview.net/forum?id=ViZcgDQjyG

    OpenReview.net. https://openreview.net/forum?id=ViZcgDQjyG

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.