encrypted-plaintext model fusion

Designs and implements model architectures and training/inference pipelines that combine subnetworks or models operating on encrypted representations and on plaintext representations, including selection of encryption schemes, secure computation protocols, and federated coordination. Builds and analyzes fusion mechanisms—probabilistic, learned, or rule-based—that integrate outputs or latent representations from encrypted and plaintext components while preserving privacy and balancing accuracy, communication, and security trade-offs.

encrypted-plaintextmodelfusion

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.23
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Privacy leakage and data security risks pose critical challenges in cross-cloud large language model (LLM) deployment and training. Method: This paper proposes a privacy-preserving federated learning framework for multi-cloud environments, featuring a dynamic model aggregation mechanism and a hybrid aggregation scheme that integrates advanced cryptographic primitives with standardized cross-cloud data collaboration protocols—all while ensuring raw data remains localized at edge devices. Contribution/Results: The framework achieves a 23% improvement in training efficiency and a 1.8% gain in model accuracy over conventional federated learning, alongside significantly enhanced convergence stability. It enables secure, efficient, and scalable cross-cloud collaborative training without compromising data sovereignty or model utility.

Addressing privacy and security in cross-cloud LLM trainingEnhancing federated learning with cryptographic and aggregation techniquesMitigating data leakage and optimizing model update aggregation

This work addresses the inefficiency and accuracy trade-off in existing encrypted neural network inference systems, which rely on fixed models for all inputs, resulting in high latency and cost. The paper proposes the first end-to-end encrypted dynamic routing framework that adaptively selects the optimal model size for Transformer inference directly on ciphertext, based on input features. By integrating secure multi-party computation (MPC), an MPC-overhead-aware encrypted router, a co-optimized model pool, and quantization strategies, the framework unifies secure routing, inference, and protocol execution while preserving the confidentiality of both data and models. Experimental results demonstrate that the approach reduces inference latency by up to 1.95× compared to state-of-the-art methods with negligible accuracy loss, offering a practical solution for scalable and secure AI inference.

Encrypted RoutingModel SelectionSecure Inference

This work addresses the security and scalability challenges in federated learning arising from adversarial gradient updates and aggregation bottlenecks by proposing the first end-to-end distributed architecture integrating zero-knowledge proofs (ZKPs). By compiling machine learning loss functions into Rank-1 Constraint Systems (R1CS), the approach enables cryptographic verification of local computations at each node without accessing raw gradients, thereby effectively mitigating model poisoning attacks. Experimental results demonstrate that the system maintains high throughput even at a scale of one thousand nodes and achieves a model accuracy retention rate of 94.2% under adversarial conditions, marking the first scalable federated learning framework that simultaneously guarantees strong security and high performance.

Distributed AIFederated LearningModel Poisoning

Securing Federated Learning against Backdoor Threats with Foundation Model Integration

Oct 23, 2024
XB
Xiaohuan Bi
🏛️ Renmin University of China | The University of Alabama at Birmingham

Foundation model (FM)-enhanced federated learning (FL) introduces a novel backdoor attack paradigm: adversaries exploit FM vulnerabilities to inject backdoors into synthetically generated data, thereby contaminating all client models via global aggregation—diverging fundamentally from conventional backdoor attacks and evading existing defenses. Method: We first identify anomalous hidden-layer activations as a unifying indicator across both classical and FM-enhanced backdoors. Based on this insight, we propose a dynamic activation-space constraint mechanism—requiring no access to original data and seamlessly embeddable into FL training. It comprises three components: (i) activation regularization, (ii) synthetic-data-driven constraint optimization, and (iii) latent-feature monitoring and pruning during federated aggregation. Contribution/Results: Evaluated on multiple benchmarks, our method reduces average attack success rate to <3% while incurring <1.2% main-task accuracy degradation—significantly outperforming state-of-the-art defenses.

Addressing ineffective existing defenses against synthetic data backdoorsMitigating hidden feature space abnormalities during model aggregationSecuring Federated Learning from novel FM-based backdoor attacks

Latest Papers

What's happening recently
View more

This work addresses the challenge of balancing privacy preservation and computational efficiency in federated learning by proposing a selective feature encryption approach based on principal component analysis (PCA). The method applies multi-party homomorphic encryption (MHE) only to sensitive features identified via PCA, while training the remaining features in plaintext. A dual-path neural network architecture is introduced, with outputs from both encrypted and plaintext paths integrated through a fusion mechanism. Additionally, an efficient packing scheme tailored to the entire network architecture is designed to minimize redundant computation. Experimental results demonstrate that the proposed approach achieves model accuracy comparable to standard federated learning while substantially reducing encryption overhead and effectively resisting reconstruction attacks, thereby enabling a synergistic optimization of privacy guarantees and computational efficiency.

computational efficiencyfeature privacyfederated learning

This work addresses the privacy risks in federated learning, where model updates may inadvertently leak sensitive user information. To mitigate this, the authors propose a novel federated learning framework that integrates homomorphic encryption with differential privacy. Specifically, homomorphic encryption enables secure aggregation of model updates in encrypted form, while differential privacy introduces calibrated noise to these updates, thereby providing dual-layer privacy protection without requiring clients to upload raw local data. The efficacy of the approach is empirically validated on real-world datasets—including Framingham, Pima Indians Diabetes, and Bank Marketing—demonstrating its ability to maintain high model accuracy while ensuring strong privacy guarantees in sensitive domains such as healthcare and finance. The study also systematically investigates the impact of data heterogeneity on performance and presents corresponding optimization strategies.

Data PrivacyFederated LearningModel Updates

This work proposes a unified privacy-preserving framework based on the CKKS homomorphic encryption scheme to mitigate the risk of privacy leakage associated with processing sensitive data in plaintext during machine learning. For the first time, it enables encrypted training of both k-nearest neighbors (KNN) and linear regression, as well as encrypted inference for multilayer perceptrons, within a single system. By integrating approximation techniques to handle non-polynomial operations and effectively managing ciphertext noise to enhance computational efficiency, the framework maintains end-to-end data encryption while achieving model accuracy comparable to that of plaintext training. The results demonstrate the practical feasibility of privacy-preserving machine learning and highlight key challenges remaining in computational overhead and functional expressiveness.

data confidentialityencrypted data traininghomomorphic encryption

While model merging can enhance the performance of large language models (LLMs), it may inadvertently introduce novel security risks that compromise alignment in the merged model. This work proposes TrojanMerge, a framework that uncovers a previously overlooked attack surface in the merging process: by embedding latent perturbations into source models under a directional consistency constraint, an adversary can induce highly harmful outputs in the merged model while preserving the individual safety and capabilities of each source model. The attack is formulated as a constrained optimization problem, leveraging Frobenius-norm-based directional alignment to precompute effective perturbation vectors. Experiments across nine LLMs from three model families demonstrate that TrojanMerge significantly increases harmful response rates in merged models without degrading source model safety or performance, and remains effective across diverse merging algorithms and hyperparameter configurations.

large language modelslatent vulnerabilitiesmodel merging

This work addresses the high inference costs, low service efficiency, and insufficient stability of large language models by proposing the first token-centric four-layer inference optimization framework. The architecture integrates multi-model fusion, model compression and quantization, compute-model co-optimization, and joint scheduling across computation, networking, and modeling. By systematically combining these key techniques, the framework substantially reduces the cost per generated token while significantly enhancing service efficiency and supply stability. It provides a holistic, efficient, stable, and cost-effective solution that enables large models to transition from being merely callable to truly operable at scale, thereby supporting their widespread deployment in real-world applications.

cost reductioninference optimizationlarge model inference

Hot Scholars

CP

Chanyoung Park

Associate Professor, KAIST
Artificial intelligenceGraph data miningRecommender systemAI for Science
SR

Swarup Ranjan Behera

Data Scientist
NLPSportsAISpeech/Audio ProcessingAudio Deepfake Detection
MM

Mohd Mujtaba Akhtar

UPES-India
Speech/Audio ProcessingAffective ComputingDeepfake Detection
RS

Rajesh Sharma

University of Tartu
Computational Social ScienceData ScienceSocial Network AnalysisSocial Computing