When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA Systems
2026-06-29T07:23:35Z•9757ddec38a34519fbc68acb2d3c329a9a1711b110de683447cd77a670fbcebe
adversarial-examplesagentic-aiarchitectural-separationautomotivebackdoordeceptionfederated-learningflexraygradient-reconstructionhardware-benchmarkinghomomorphic-encryptionllmmitre-attackpower-analysisprivacyprivate-set-intersectionprompt-injectionre-identificationshared-embeddingtiming-attacktinymltransparency-log
What happened
Collection of new security-relevant research (arXiv, 29 Jun 2026) covering multiple high-impact risks: (1) A data-free, stealthy backdoor attack where a malicious federated aggregator reconstructs client training samples from uploaded gradients and injects advertisement-style backdoors into LLM-based QA systems with near-100% success while preserving clean-task fidelity. (2) A structural impossibility result showing prompt-injection cannot be perfectly prevented in shared-embedding sequence models without architectural separation of instruction and data. (3) AdvScan: a black-box runtime advers
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_cr
- Record identifier
- 9757ddec38a34519fbc68acb2d3c329a9a1711b110de683447cd77a670fbcebe
- Enrichment time
- 2026-06-29T07:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.