Securing Federated Learning: A Hybrid Defense Against Poison Injection Attacks in LLM Presentation uri icon

Description

  • Federated learning has shown promise in ensuring data privacy in healthcare settings. Despite this, several attacks still leave Large Language Models (LLMs) utilizing this aggregation model vulnerable to data leaks and model degradation. One such type of attack is a poison injection attack, where an attacker will inject “poisoned” inputs with the specific purpose of degrading the effectiveness of the model or priming it to leak memorized data points. Several techniques have been claimed to remedy such an attack. This paper explores three remedies: differential privacy (DP), Krum filtering, and adaptive trust aggregation. We will use a simulated federated learning environment to test the effectiveness, efficiency, and model health of these three techniques. We will also propose a new framework combining these techniques to create a model optimized against poison injection attacks.

Date/time Interval

  • 2025-10-01 - 2025-10-31