SecureGate: Learning When to Reveal PII Safely via Token-Gated Dual-Adapters for Federated LLMs
Mohamed Shaaban, Mohamed Elmahallawy
Abstract
Federated learning (FL) enables collaborative training across organizational silos without sharing raw data, making it attractive for privacy-sensitive applications. With the rapid adoption of large language models (LLMs), federated fine-tuning of generative LLMs has gained attention as a way to leverage distributed data while preserving confidentiality. However, this setting introduces fundamental challenges: (i) privacy leakage of personally identifiable information (PII) due to LLM memorization, and (ii) a persistent tension between global generalization and local utility under heterogeneous data. Existing defenses, such as data sanitization and differential privacy, reduce leakage but often degrade downstream performance. We propose SECUREGATE, a privacy-aware federated fine-tuning framework for LLMs that provides fine-grained privacy control without sacrificing utility. SECUREGATE employs a dualadapter LoRA architecture: a secure adapter that learns sanitized, globally shareable representations, and a revealing adapter that captures sensitive, organization-specific knowledge. A token-controlled gating module selectively activates these adapters at inference time, enabling controlled information disclosure without retraining. Extensive experiments across multiple LLMs and real-world datasets show that SECUREGATE improves task utility while substantially reducing PII leakage, achieving up to a 31.66× reduction in inference attack accuracy and a 17.07× reduction in extraction recall for unauthorized requests. Additionally, it maintains 100% routing reliability to the correct adapter and incurs only minimal computational and communication overhead. Code is available at https://github.com/ wsu-cyber-security-lab-ai/SecureGate .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 73cfc62f-9913-4e88-856a-0df0ac7a828fBuilds on6
- Heterogeneous Personalized Federated Learning by Local-Global Updates Mixing via Convergence RateMeirui Jiang, Anjie Le, Xiaoxiao Li, Qi DouICLR 2024 · 13 citations
- Towards Trustworthy Federated Learning with Untrusted ParticipantsYoussef Allouah, Rachid Guerraoui, John StephanICML 2025
- Hot-pluggable Federated Learning: Bridging General and Personalized FL via Dynamic SelectionLei Shen, Zhenheng Tang, Lijun Wu, Yonggang Zhang et al.ICLR 2025
- Generated Data with Fake Privacy: Hidden Dangers of Fine-tuning Large Language Models on Generated DataAtilla Akkus, Masoud Poorghaffar Aghdam, Mingjie Li, Junjie Chu et al.USENIX Security 2025
- Janus: Dual-Server Multi-Round Secure Aggregation with Verifiability for Federated LearningLang Pu, Jingjing Gu, Chao Lin, Xinyi HuangICML 2025
Related papers
- Adaptive LoRA Experts Allocation and Selection for Federated Fine-TuningLei Wang, Jieming Bian, Letian Zhang, Jie XuNeurIPS 2025 · 14 citations
- Personalized Federated Fine-Tuning for LLMs via Data-Driven Heterogeneous Model ArchitecturesYicheng Zhang, Zhen Qin, Zhaomin Wu, Jian Hou et al.WWW 2026 · 9 citations
- Differentially Private Federated Low Rank Adaptation Beyond Fixed-MatrixMing Wen, Jiaqi Zhu, Yuedong Xu, Yipeng Zhou et al.NeurIPS 2025 · 6 citations
- Efficient and Differentially Private Federated LLM Fine-Tuning on Heterogeneous ClientsNan Yan, Yuqing Li, Xiong Wang, Jing Chen et al.KDD 2026
- FLoRA: Federated Fine-Tuning Large Language Models with Heterogeneous Low-Rank AdaptationsZiyao Wang, Zheyu Shen, Yexiao He, Guoheng Sun et al.NeurIPS 2024 · 227 citations
