Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning
Tianyu Qi, Lei Xue, Yufeng Zhan, Xiaobo Ma
Abstract
The growing adoption of large pre-trained models in edge computing has made deploying model inference on mobile clients both practical and popular. These devices are inherently vulnerable to direct adversarial attacks, which pose a substantial threat to the robustness and security of deployed models. Federated adversarial training (FAT) has emerged as an effective solution to enhance model robustness while preserving client privacy. However, FAT frequently produces a generalized global model, which struggles to address the diverse and heterogeneous data distributions across clients, resulting in insufficiently personalized performance, while also encountering substantial communication challenges during the training process. In this paper, we propose Sylva, a personalized collaborative adversarial training framework designed to deliver customized defense models for each client through a two-phase process. In Phase 1, Sylva employs LoRA for local adversarial fine-tuning, enabling clients to personalize model robustness while drastically reducing communication costs by uploading only LoRA parameters during federated aggregation. In Phase 2, a game-based layer selection strategy is introduced to enhance accuracy on benign data, further refining the personalized model. This approach ensures that each client receives a tailored defense model that balances robustness and accuracy effectively. Extensive experiments on benchmark datasets demonstrate that Sylva can achieve up to 50× improvements in communication efficiency compared to state-of-the-art algorithms, while achieving up to 29.5% and 50.4% enhancements in adversarial robustness and benign accuracy, respectively.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f96b6968-4faf-4b1e-8584-d49e626ad4bfRelated papers
- FedPissa: Towards Federated Personalized Adaptation of Foundation Models via LoRA Subspace MappingWenwen He, Wenke Huang, Yi Liu, Jian Liang et al.ICML 2026
- SHE-LoRA: Selective Homomorphic Encryption for Federated Tuning with Heterogeneous LoRAJianmin Liu, Li Yan, Borui Li, Lei Yu et al.ICLR 2026 · 5 citations
- Towards Robust Parameter-Efficient Fine-Tuning for Federated LearningXiuwen Fang, Mang YeNeurIPS 2025 · 2 citations
- HeteroFL-LoRA: Federated LoRA Fine-Tuning Across Heterogeneous LFMs via Singular Value CollaborationZhuojia Wu, Qi Zhang, Xuerong Zhao, Duoqian Miao et al.KDD 2026
- Combating Exacerbated Heterogeneity for Robust Models in Federated LearningJianing Zhu, Jiangchao Yao, Tongliang Liu, Quanming Yao et al.ICLR 2023 · 2 citations
