A Resilient Federated Learning Framework for LLM Security in Healthcare -- 11th IEEE International Symposium on Smart Electronic Systems (IEEE – iSES)
Academic Article
Overview
Overview
Abstract
Federated learning (FL) has emerged as a promising paradigm for preserving data privacy in healthcare applications. However, large language models (LLMs) trained under this framework remain susceptible to various attacks that can expose sensitive data and impair model performance. These attacks include backdoor, model inversion, model inference, etc. All of these attempt to infringe on either the confidentiality or integrity of the LLM, posing serious risks for the healthcare industry. However, several countermeasures have been proposed to mitigate such attacks, yet their efficacy remains uncertain. We have evaluated federated learning (FL) under three progressively stronger defense configurations: (i) (i) no defense, representing a vulnerable baseline; (ii) a standard defense, combining differential privacy (DP), Krum filtering, and the adaptive trust algorithm (ATA); and (iii) a comprehensive defense, which extends the baseline with homomorphic encryption (HE) and secure aggregation (SA).Additionally, we assessed our FL environment to evaluate the effectiveness, efficiency, and overall model health across the three configurations. This analysis demonstrates that our full defense framework provides a robust solution for maintaining data confidentiality and integrity in FL-based LLMs, both of which are critical for deployment in healthcare.