Safely Learning with Private Data: A Federated Learning Framework for Large Language Model
Jiaying Zheng, Hainan Zhang, Lingxiang Wang, Wangjie Qiu, Hongwei Zheng, Zhiming Zheng
摘要
Private data, being larger and quality-higher than public data, can greatly improve large language models (LLM). However, due to privacy concerns, this data is often dispersed in multiple silos, making its secure utilization for LLM training a challenge. Federated learning (FL) is an ideal solution for training models with distributed private data, but traditional frameworks like FedAvg are unsuitable for LLM due to their high computational demands on clients. An alternative, split learning, offloads most training parameters to the server while training embedding and output layers locally, making it more suitable for LLM. Nonetheless, it faces significant challenges in security and efficiency. Firstly, the gradients of embeddings are prone to attacks, leading to potential reverse engineering of private data. Furthermore, the server’s limitation of handling only one client’s training request at a time hinders parallel training, severely impacting training efficiency. In this paper, we propose a Federated Learning framework for LLM, named FL-GLM, which prevents data leakage caused by both server-side and peer-client attacks while improving training efficiency. Specifically, we first place the input block and output block on local client to prevent embedding gradient attacks from server. Secondly, we employ key-encryption during client-server communication to prevent reverse engineering attacks from peer-clients. Lastly, we employ optimization methods like client-batching or server-hierarchical, adopting different acceleration methods based on the actual computational capabilities of the server. Experimental results on NLU and generation tasks demonstrate that FL-GLM achieves comparable metrics to centralized chatGLM model, validating the effectiveness of our federated learning framework.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Privacy Perceptions of Custom GPTs by Users and CreatorsRongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist 等CHI 2025 · 被引用 35 次
- Defending Against Sophisticated Poisoning Attacks with RL-based Aggregation in Federated LearningYujing Wang, Hainan Zhang, Sijia Wen, Wangjie Qiu 等AAAI 2025 · 被引用 4 次
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 等S&P 2026 · 被引用 4 次
- Feature Coding in the Era of Large Models: Dataset, Test Conditions, and BenchmarkChangsheng Gao, Yifan Ma, Qiaoxi Chen, Yenan Xu 等ICCV 2025 · 被引用 3 次
- Taming Noise-Induced Prototype Degradation for Privacy-Preserving Personalized Federated Fine-TuningYuhua Wang, Qinnan Zhang, Xiaodong Li, Huan Zhang 等CVPR 2026 · 被引用 1 次
它引用的顶会 Paper8
- Large Language Models Can Be Strong Differentially Private LearnersXuechen Li, Florian Tramèr, Percy Liang, Tatsunori HashimotoICLR 2022 · 被引用 502 次
- Differentially Private Fine-tuning of Language ModelsDa Yu, Saurabh Naik, Arturs Backurs, Sivakanth Gopi 等ICLR 2022 · 被引用 494 次
- UniLMv2: Pseudo-Masked Language Models for Unified Language Model Pre-TrainingHangbo Bao, Li Dong, Furu Wei, Wenhui Wang 等ICML 2020 · 被引用 423 次
- GLM-130B: An Open Bilingual Pre-trained ModelAohan Zeng, Xiao Liu, Zhengxiao Du, Zihan Wang 等ICLR 2023 · 被引用 295 次
- Multi-View Sequence-to-Sequence Models with Conversational Structure for Abstractive Dialogue SummarizationJiaao Chen, Diyi YangEMNLP 2020 · 被引用 121 次
相关 Paper
- FedSEA-LLaMA: A Secure, Efficient and Adaptive Federated Splitting Framework for Large Language ModelsZishuai Zhang, Hainan Zhang, Weihua Li, Qinnan Zhang 等AAAI 2026
- Fast Generation-Based Gradient Leakage Attacks against Highly Compressed GradientsDongyun Xue, Haomiao Yang, Mengyu Ge, Jingwei Li 等INFOCOM 2023 · 被引用 4 次
- A New Federated Learning Framework Against Gradient Inversion AttacksPengxin Guo, Shuang Zeng, Wenhao Chen, Xiaodan Zhang 等AAAI 2025 · 被引用 5 次
- PrivSplit: A Lossless Method for Prompt Privacy in Distributed Parameter-Efficient Fine-TuningWujia Niu, Lan Zhang, Haoran Cheng, Shen LiWWW 2026
- Recovering Private Text in Federated Learning of Language ModelsSamyak Gupta, Yangsibo Huang, Zexuan Zhong, Tianyu Gao 等NeurIPS 2022 · 被引用 120 次
