{"id":"https://openalex.org/W7156146153","doi":"https://doi.org/10.1145/3774904.3792182","title":"Reconstructing Training Data from Adapter-based Federated Large Language Models","display_name":"Reconstructing Training Data from Adapter-based Federated Large Language Models","publication_year":2026,"publication_date":"2026-04-12","ids":{"openalex":"https://openalex.org/W7156146153","doi":"https://doi.org/10.1145/3774904.3792182"},"language":null,"primary_location":{"id":"doi:10.1145/3774904.3792182","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3792182","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3774904.3792182","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5123997939","display_name":"Silong Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Silong Chen","raw_affiliation_strings":["National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0009-0003-3904-3374","affiliations":[{"raw_affiliation_string":"National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5057427094","display_name":"Yuchuan Luo","orcid":"https://orcid.org/0000-0002-0720-4925"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuchuan Luo","raw_affiliation_strings":["National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-0720-4925","affiliations":[{"raw_affiliation_string":"National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074351272","display_name":"Guilin Deng","orcid":"https://orcid.org/0000-0001-8352-9759"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guilin Deng","raw_affiliation_strings":["National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0001-8352-9759","affiliations":[{"raw_affiliation_string":"National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013831310","display_name":"Y Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Yi Liu","raw_affiliation_strings":["City University of Hong Kong, Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0000-0002-0811-6150","affiliations":[{"raw_affiliation_string":"City University of Hong Kong, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134677236","display_name":"Ming Xu","orcid":"https://orcid.org/0000-0002-2657-5764"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ming Xu","raw_affiliation_strings":["National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-2657-5764","affiliations":[{"raw_affiliation_string":"National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082564456","display_name":"Shaojing Fu","orcid":"https://orcid.org/0000-0002-7275-8190"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shaojing Fu","raw_affiliation_strings":["National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-7275-8190","affiliations":[{"raw_affiliation_string":"National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5013643572","display_name":"Xiaohua Jia","orcid":"https://orcid.org/0000-0001-8702-8302"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Xiaohua Jia","raw_affiliation_strings":["City University of Hong Kong, Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0000-0001-8702-8302","affiliations":[{"raw_affiliation_string":"City University of Hong Kong, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5123997939"],"corresponding_institution_ids":["https://openalex.org/I170215575"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.96236547,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2602","last_page":"2613"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.39879998564720154,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.39879998564720154,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.23250000178813934,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.038600001484155655,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.5555999875068665},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.4726000130176544},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.4359000027179718},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.4212000072002411},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.4088999927043915},{"id":"https://openalex.org/keywords/semantic-equivalence","display_name":"Semantic equivalence","score":0.40619999170303345},{"id":"https://openalex.org/keywords/adapter","display_name":"Adapter (computing)","score":0.37599998712539673},{"id":"https://openalex.org/keywords/federated-learning","display_name":"Federated learning","score":0.3736000061035156},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.352400004863739}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8062999844551086},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.5555999875068665},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.4726000130176544},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.4359000027179718},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.4212000072002411},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4196000099182129},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.4088999927043915},{"id":"https://openalex.org/C37926939","wikidata":"https://www.wikidata.org/wiki/Q7449061","display_name":"Semantic equivalence","level":4,"score":0.40619999170303345},{"id":"https://openalex.org/C177284502","wikidata":"https://www.wikidata.org/wiki/Q1005390","display_name":"Adapter (computing)","level":2,"score":0.37599998712539673},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.3736000061035156},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3601999878883362},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.352400004863739},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3416000008583069},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3411000072956085},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.337799996137619},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.3319999873638153},{"id":"https://openalex.org/C160920958","wikidata":"https://www.wikidata.org/wiki/Q7662746","display_name":"Synthetic data","level":2,"score":0.323199987411499},{"id":"https://openalex.org/C2781181686","wikidata":"https://www.wikidata.org/wiki/Q4226068","display_name":"Coherence (philosophical gambling strategy)","level":2,"score":0.3221000134944916},{"id":"https://openalex.org/C2776945810","wikidata":"https://www.wikidata.org/wiki/Q17006654","display_name":"Data anonymization","level":3,"score":0.3192000091075897},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.31859999895095825},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3107999861240387},{"id":"https://openalex.org/C22019652","wikidata":"https://www.wikidata.org/wiki/Q331309","display_name":"Overfitting","level":3,"score":0.3050999939441681},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.29820001125335693},{"id":"https://openalex.org/C122783720","wikidata":"https://www.wikidata.org/wiki/Q183065","display_name":"Interpreter","level":2,"score":0.28769999742507935},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.27950000762939453},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.2770000100135803},{"id":"https://openalex.org/C139807058","wikidata":"https://www.wikidata.org/wiki/Q352374","display_name":"Adaptation (eye)","level":2,"score":0.27090001106262207},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.26910001039505005},{"id":"https://openalex.org/C71901391","wikidata":"https://www.wikidata.org/wiki/Q7126699","display_name":"Upload","level":2,"score":0.267300009727478},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.2662999927997589},{"id":"https://openalex.org/C2778476105","wikidata":"https://www.wikidata.org/wiki/Q628539","display_name":"Workload","level":2,"score":0.265500009059906},{"id":"https://openalex.org/C46686674","wikidata":"https://www.wikidata.org/wiki/Q466303","display_name":"Boosting (machine learning)","level":2,"score":0.25949999690055847},{"id":"https://openalex.org/C2780154230","wikidata":"https://www.wikidata.org/wiki/Q513420","display_name":"Undo","level":2,"score":0.2565999925136566},{"id":"https://openalex.org/C2777042071","wikidata":"https://www.wikidata.org/wiki/Q6509304","display_name":"Leakage (economics)","level":2,"score":0.2522999942302704}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3774904.3792182","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3792182","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3774904.3792182","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3792182","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.40973901748657227,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W2163455955","https://openalex.org/W2251939518","https://openalex.org/W2744999500","https://openalex.org/W2970408908","https://openalex.org/W2978670439","https://openalex.org/W3080879265","https://openalex.org/W3101498587","https://openalex.org/W3153675281","https://openalex.org/W3176828726","https://openalex.org/W4206199121","https://openalex.org/W4283208007","https://openalex.org/W4285247752","https://openalex.org/W4285605911","https://openalex.org/W4367046615","https://openalex.org/W4385572058","https://openalex.org/W4385764384","https://openalex.org/W4387212306","https://openalex.org/W4389520700","https://openalex.org/W4389524048","https://openalex.org/W4393148063","https://openalex.org/W4393148491","https://openalex.org/W4396736351","https://openalex.org/W4396929025","https://openalex.org/W4401857637","https://openalex.org/W4401863415","https://openalex.org/W4402264897","https://openalex.org/W4403577837","https://openalex.org/W4409657290","https://openalex.org/W4410089374","https://openalex.org/W4415798667"],"related_works":[],"abstract_inverted_index":{"Adapter-based":[0],"Federated":[1],"Large":[2],"Language":[3],"Models":[4],"(FedLLMs)":[5],"are":[6,192],"widely":[7],"adopted":[8],"to":[9,40,52,77],"reduce":[10],"the":[11,29,67,78,112,179],"computational,":[12],"storage,":[13],"and":[14,31,44,92,118,139,174,190],"communication":[15],"overhead":[16],"of":[17,81,115],"full-parameter":[18],"fine-tuning":[19],"for":[20],"web-scale":[21],"applications":[22],"while":[23],"preserving":[24],"user":[25],"privacy.":[26],"By":[27],"freezing":[28],"backbone":[30],"training":[32],"only":[33],"compact":[34],"low-rank":[35,58,113],"adapters,":[36],"these":[37],"methods":[38],"appear":[39],"limit":[41],"gradient":[42],"leakage":[43,63],"thwart":[45],"existing":[46],"Gradient":[47],"Inversion":[48],"Attacks":[49],"(GIAs).":[50],"Contrary":[51],"this":[53],"assumption,":[54],"we":[55],"show":[56],"that":[57,146,182],"adapters":[59],"create":[60],"new,":[61],"exploitable":[62],"channels.":[64],"We":[65],"propose":[66],"Unordered-word-bag-based":[68],"Text":[69],"Reconstruction":[70],"(UTR)":[71],"attack,":[72],"a":[73,168],"novel":[74],"GIA":[75],"tailored":[76],"unique":[79],"structure":[80],"adapter-based":[82],"FedLLMs.":[83],"UTR":[84,147],"overcomes":[85],"three":[86],"core":[87],"challenges\u2014low-dimensional":[88],"gradients,":[89,117],"frozen":[90,105],"backbones,":[91],"combinatorially":[93],"large":[94,157],"reconstruction":[95,150],"spaces\u2014by:":[96],"(i)":[97],"inferring":[98],"token":[99],"presence":[100],"from":[101],"attention":[102],"patterns":[103],"in":[104,176],"layers,":[106],"(ii)":[107],"performing":[108],"sentence-level":[109],"inversion":[110],"within":[111],"subspace":[114],"adapter":[116],"(iii)":[119],"enforcing":[120],"semantic":[121],"coherence":[122],"through":[123],"constrained":[124],"greedy":[125],"decoding":[126],"guided":[127],"by":[128],"language":[129],"priors.":[130],"Extensive":[131],"experiments":[132],"across":[133],"diverse":[134],"models":[135],"(GPT2-Large,":[136],"BERT,":[137],"Qwen2.5-7B)":[138],"datasets":[140],"(CoLA,":[141],"SST-2,":[142],"Rotten":[143],"Tomatoes)":[144],"demonstrate":[145],"achieves":[148],"near-perfect":[149],"accuracy":[151],"(ROUGE-1/2":[152],">":[153],"99),":[154],"even":[155],"with":[156],"batch":[158],"sizes\u2014settings":[159],"where":[160],"prior":[161],"GIAs":[162],"fail":[163],"completely.":[164],"Our":[165,188],"results":[166],"reveal":[167],"fundamental":[169],"tension":[170],"between":[171],"parameter":[172],"efficiency":[173],"privacy":[175],"FedLLMs,":[177],"challenging":[178],"prevailing":[180],"belief":[181],"lightweight":[183],"adaptation":[184],"inherently":[185],"enhances":[186],"security.":[187],"code":[189],"data":[191],"available":[193],"at":[194],"https://github.com/shwksnshwowk-wq/GIA":[195]},"counts_by_year":[],"updated_date":"2026-04-28T06:12:00.211691","created_date":"2026-04-28T00:00:00"}
