Life sciences · Preprint
arXiv · August 19, 2026
Posted before peer review. The findings may change or fail to hold.
FedLNS is a proposed server-side screening method for detecting malicious client updates in federated large language model training, using normalization-layer signatures without additional data exchange or external datasets. Experiments on three model architectures show lower test perplexity than baselines under 40% population-level target manipulation in simulated settings; generalizability to real-world federated deployments and robustness under other attack strategies remain unvalidated.
Preprint. Simulated federated learning clients (200 per experiment) training language models from scratch with both IID and non-IID data distributions. Intervention: FedLNS: server-side malicious-update screening using normalization-layer signature extraction and cross-client reference validation. Compared with: Six baseline methods (not named in abstract); standard federated learning without screening.
FedLNS achieves lower test perplexity than the strongest of six baselines for GPT-style, BERT-style, and LLaMA-style models under 40% population-level target manipulation Method works under both IID and non-IID data partitions across three model architectures No additional client-to-server parameter or metadata exchange required compared to standard federated learning
Safety was not reported in the material analysed. Check the source before drawing any conclusion about harm.
The source did not state who this applies to in practice.
This is an unrefereed arXiv preprint presenting a novel technical method for federated learning security; it reports experimental results but has not undergone peer review.
As stated by the source record.
Quoted from the source exactly as published.
Graded across the dimensions that decide whether you should act, each from what the source actually supports. There is no single score, and where a dimension was not assessed it says so.
Federated training enables language models to learn from distributed private text, but the server cannot directly verify the local supervision or optimization process that produces each client update. A malicious client can therefore train on corrupted targets, introduce incorrect context-token associations, and degrade the global model through repeated aggregation. Such degradation can also increase the risk of unreliable or hallucinatory generation. We propose Federated Learning with Normalization Signatures (FedLNS), a server-side framework for lightweight malicious-update screening. FedLNS represents each client update through changes in trainable normalization-layer parameters and screens suspicious updates against a robust, history-aware cross-client reference. Because the signatures are extracted at the server from the returned local models, FedLNS requires no additional client-to-server parameter or metadata exchange compared to standard federated learning (FL) methods. After screening, the retained full-model updates can be aggregated using standard FL or another compatible aggregation rule. FedLNS requires no raw client data, trusted server dataset, labeled attack examples, or separately trained detector. Experiments on GPT-style, BERT-style, and LLaMA-style models trained from scratch with 200 clients show that, under 40% population-level target manipulation, FedLNS achieves lower test perplexity than the strongest of six baselines for all three architectures under both IID (independently and identically distributed) and non-IID data partitions.
Taken from the source record, never inferred. Follow any of these and new work involving them reaches your briefing.