Safe-FedLLM: Delving into the Safety of Federated Large Language Models
arXiv:2601. 07177v5 Announce Type: replace-cross Abstract: Federated learning (FL) addresses privacy and data-silo issues in the training of large language models (LLMs).
arXiv:2607. 19674v1 Announce Type: cross Abstract: Federated Graph Neural Networks (FedGNNs) are highly vulnerable to backdoor poisoning, yet existing defenses typically rely on rule-based approaches that lack semantic understanding, making them vulnerable to stealthy triggers and harmful to benign structures.
arXiv:2601. 07177v5 Announce Type: replace-cross Abstract: Federated learning (FL) addresses privacy and data-silo issues in the training of large language models (LLMs).
arXiv:2605. 07961v2 Announce Type: replace Abstract: Federated fine-tuning (FFT) has emerged as a privacy-preserving paradigm for collaboratively adapting large language models (LLMs).
The paper introduces STAG, a stealthy trojan attack framework targeting Graph Foundation Models (GFMs) that operate on text‑attributed graphs (TAGs). STAG jointly generates graph triggers and soft‑prompt text cues so that both modalities converge to a malicious target class while keeping the trigger subgraph structurally similar to the original and the trigger text readable. Experiments on several TAG datasets and GFMs confirm that STAG achieves high attack success rates while remaining difficult to detect.
arXiv:2607. 03350v1 Announce Type: cross Abstract: Malicious Python packages have become a major threat to software supply chain ecosystems due to the widespread adoption of open-source repositories such as PyPI.
The paper evaluates privacy risks in graph neural networks enhanced by large language models (LLMs). Using a five‑stage framework, the authors test six real‑world text‑attributed graph datasets with 42 model configurations and six privacy attack methods across link, label, and membership inference threats. Results show that LLM‑enhanced GNNs are more vulnerable than shallow baselines, with semantic enrichment amplifying exploitable signals, and that differential privacy can reduce risk but at a significant cost to utility.
FedLNS is a server‑side framework that screens federated learning updates by representing each client’s contribution through changes in trainable normalization‑layer parameters, creating lightweight signatures that can be compared against a history‑aware cross‑client reference. The method requires no extra client‑to‑server communication, raw data, or labeled attack examples, and after screening, the remaining full‑model updates are aggregated with standard federated learning rules. Experiments on GPT‑style, BERT‑style, and LLaMA‑style models with 200 clients demonstrate that FedLNS achieves lower test perplexity than six baselines even when 40% of the population performs target manipulation under both IID and non‑IID data partitions.
FedNIA is a defense framework for federated learning that identifies and excludes malicious clients without needing a central test dataset. It works by injecting random noise inputs and analyzing layerwise activation patterns with an autoencoder to detect abnormal behaviors caused by data poisoning. The method can counter various attack types—including sample poisoning, label flipping, and backdoors—even when multiple attackers collaborate, and shows strong performance on non‑iid federated datasets.
CACTUS is a new backdoor attack for decentralized federated learning that uses mask‑guided, modality‑specific operators to convert label‑consistent semantic pairs into target‑directed representation shifts. By isolating trigger effects and applying them counterfactually to clean embeddings before peer aggregation, CACTUS can propagate backdoors across repeated aggregation rounds. Experiments on speech, text, tabular, and image tasks show that with 30% malicious nodes, CACTUS achieves a mean attack success rate of 51.2% on Speech Commands and the highest mean ASR among evaluated attacks on three of four modalities, with success varying by network topology and malicious‑node ratio.
arXiv:2608.29054v1 Announce Type: new Abstract: Graph Neural Networks (GNNs) have emerged as a cornerstone for representing complex relational dependencies in diverse multimedia tasks, particularly i...
TH-GNN is a heterogeneous temporal graph neural network designed to detect shilling attacks generated by large language model (LLM) agents. It combines a two‑layer Heterogeneous Graph Transformer with per‑type and per‑relation attention, learnable sinusoidal temporal encodings, cross‑modal attention that fuses user embeddings with frozen RoBERTa representations of reviews and item descriptions, and a GRU that models log inter‑arrival times. Across five attack families and four benchmark datasets, TH‑GNN achieves a grand‑mean F1 score of 0.870, surpassing the best text‑only baseline on Agent4SR attacks by 10.9 percentage points and 11.5 percentage points at the lowest injection rate.
arXiv:2606. 15277v1 Announce Type: cross Abstract: Graph-based recommender systems are highly effective at extracting collaborative signals from user--item interactions, and federated learning (FL) allows these models to be trained while preserving user privacy.
arXiv:2608.21137v1 Announce Type: new Abstract: Decentralized Federated Learning (DFL) promises trust-free collaborative learning by replacing the centralized parameter server with peer-to-peer model...