Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual Approach
Guilin Deng, Silong Chen, Yuchuan Luo, Yi Liu, Songlei Wang, Zhiping Cai, Lin Liu, Xiaohua Jia, Shaojing Fu
Abstract
Federated Large Language Models (FedLLMs) enable multiple parties to collaboratively fine-tune LLMs without sharing raw data, addressing challenges of limited resources and privacy concerns. Despite data localization, shared gradients can still expose sensitive information through membership inference attacks (MIAs). However, FedLLMs' unique properties, i.e., massive parameter scales, rapid convergence, and sparse, non-orthogonal gradients, render existing MIAs ineffective. To address this gap, we propose ProjRes, the first projection residuals-based passive MIA tailored for FedLLMs. ProjRes leverages hidden embedding vectors as sample representations and analyzes their projection residuals on the gradient subspace to uncover the intrinsic link between gradients and inputs. It requires no shadow models, auxiliary classifiers, or historical updates, ensuring efficiency and robustness. Experiments on four benchmarks and four llMs show that ProjRes achieves near 100% accuracy, outperforming prior methods by up to 75.75%. While strong DP can effectively mitigate ProjRes, it does so by substantially degrading model utility. Our findings reveal a previously overlooked privacy vulnerability in FedLLMs and call for a re-examination of their security assumptions. Our code and data are available at link.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c31dd453-4b98-41f1-90ac-e70d1ce2a0fcBuilds on21
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Systematic Evaluation of Privacy Risks of Machine Learning ModelsLiwei Song, Prateek MittalUSENIX Security 2021 · 483 citations
- QA-LoRA: Quantization-Aware Low-Rank Adaptation of Large Language ModelsYuhui Xu, Lingxi Xie, Xiaotao Gu, Xin Chen et al.ICLR 2024 · 179 citations
- Federated Fine-tuning of Large Language Models under Heterogeneous Tasks and Client ResourcesJiamu Bai, Daoyuan Chen, Bingchen Qian, Liuyi Yao et al.NeurIPS 2024 · 178 citations
Related papers
- Order of Magnitude Speedups for LLM Membership InferenceRongting Zhang, Martin Bertran Lopez, Aaron RothEMNLP 2024 · 1 citation
- Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision ModelsQuan Minh Nguyen, Minh N. Vu, Truc Nguyen, My T. ThaiICML 2025
- LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language ModelsYihao Liu, Xinqi Lyu, Dong Wang, Yanjie Li et al.NeurIPS 2025 · 3 citations
- Membership Inference Attack Against Large Language Model-Based Recommendation Systems: A New Distillation-Based ParadigmCuihong Li, Xiaowen Huang, Chuanhuan Yin, Jitao SangAAAI 2026
- Membership Inference Attacks against Large Vision-Language ModelsZhan Li, Yongtao Wu, Yihang Chen, Francesco Tonin et al.NeurIPS 2024 · 43 citations
