<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">79321</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2026.079321</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>When Federated Learning Meets Large Language Models: Taxonomy, Challenges, and Opportunities</article-title>
<alt-title alt-title-type="left-running-head">When Federated Learning Meets Large Language Models: Taxonomy, Challenges, and Opportunities</alt-title>
<alt-title alt-title-type="right-running-head">When Federated Learning Meets Large Language Models: Taxonomy, Challenges, and Opportunities</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Jiang</surname><given-names>Shan</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>You</surname><given-names>Wenxin</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Zhang</surname><given-names>Haoran</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Xuan</surname><given-names>Shichang</given-names></name><xref ref-type="aff" rid="aff-3">3</xref><xref rid="cor1" ref-type="corresp">&#x002A;</xref><email>xuanshichang@hrbeu.edu.cn</email></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Shen</surname><given-names>Jiaxing</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<aff id="aff-1"><label>1</label><institution>School of Software Engineering, Sun Yat-Sen University</institution>, <addr-line>Zhuhai</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>School of Art and Design, Guangzhou Institute of Science and Technology</institution>, <addr-line>Guangzhou</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>College of Computer Science and Technology, Harbin Engineering University</institution>, <addr-line>Harbin</addr-line>, <country>China</country></aff>
<aff id="aff-4"><label>4</label><institution>School of Data Science, Lingnan University</institution>, <addr-line>Hong Kong SAR</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Shichang Xuan. Email: <email>xuanshichang@hrbeu.edu.cn</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>15</day><month>06</month><year>2026</year>
</pub-date>
<volume>88</volume>
<issue>2</issue>
<elocation-id>1</elocation-id>
<history>
<date date-type="received">
<day>19</day>
<month>01</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>20</day>
<month>04</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Authors. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Authors</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_79321.pdf"></self-uri>
<abstract>
<p>Large Language Models (LLMs) have been playing a transformative role in natural language understanding and generation, yet adapting LLMs to domain-specific and privacy-sensitive data remains challenging under centralized training. Federated Learning (FL) provides a promising alternative by enabling training LLMs collaboratively without sharing raw data. However, integrating FL and LLMs introduces new challenges, including model size, device heterogeneity, non-IID data, and alignment requirements. This survey offers a structured overview of the federated LLM ecosystem. We present a comprehensive taxonomy encompassing system architectures, advanced data strategies for addressing heterogeneity, and retrieval-augmented generation in federated contexts. Additionally, we review efficient adaptation methods that enable LLM tuning on resource-constrained clients and analyze data security and privacy concerns. We conclude by summarizing emerging applications in healthcare, industry, software engineering, and finance, and by outlining open problems and research opportunities for scalable, secure, and responsible federated LLM deployment.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Large language models</kwd>
<kwd>federated learning</kwd>
<kwd>foundation models</kwd>
<kwd>federated large language models</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>HK RGC Theme-Based Research Scheme</funding-source>
<award-id>T43-513/23-N</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Pearl River Talent Plan</funding-source>
<award-id>2024QN11X183</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The advent of Large Language Models (LLMs) has revolutionized artificial intelligence and empowered machines with powerful capabilities in natural language understanding, reasoning, and generation [<xref ref-type="bibr" rid="ref-1">1</xref>]. LLMs, such as GPT [<xref ref-type="bibr" rid="ref-2">2</xref>] and LLaMA [<xref ref-type="bibr" rid="ref-3">3</xref>], leverage massive corpora and billions of parameters to achieve emergent behaviors that were previously unattainable. Despite the advancements, deploying LLMs in real-world applications encounters a critical challenge: the need for vast, diverse datasets to fine-tune LLMs conflicts directly with increasingly stringent data privacy regulations and the proprietary character of domain-specific information [<xref ref-type="bibr" rid="ref-4">4</xref>]. Centralized training, which requires assembling raw data into a central authority, incurs high risks of data leakage and violates data sovereignty laws.</p>
<p>Federated Learning (FL) has been considered as a transformative paradigm to resolve the tension of data privacy [<xref ref-type="bibr" rid="ref-5">5</xref>]. By enabling collaborative model training across decentralized devices without exchanging raw data, FL provides a mechanism to harness the collective intelligence of siloed datasets while preserving privacy [<xref ref-type="bibr" rid="ref-6">6</xref>]. The integration of FL and LLM, i.e., federated LLM, promises to unlock new frontiers in personalized healthcare, secure financial analysis, and industrial automation. Unlike traditional FL, which typically focuses on training small-scale models from scratch, federated LLM primarily addresses the challenges of fine-tuning and aligning pre-trained LLMs in resource-constrained, heterogeneous environments.</p>
<p>The rapid evolution of federated LLM has catalyzed a surge in academic research, resulting in a plethora of architectures, optimization techniques, specialized toolkits, and benchmarks [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>]. Frameworks such as FederatedScope-LLM [<xref ref-type="bibr" rid="ref-9">9</xref>] and OpenFedLLM [<xref ref-type="bibr" rid="ref-10">10</xref>] have been developed to standardize the deployment of LLMs on decentralized infrastructure, providing researchers with robust environments for benchmarking performance. Similarly, comprehensive toolkits bridging continuous pre-training and alignment [<xref ref-type="bibr" rid="ref-11">11</xref>] have streamlined the transition from general-purpose models to domain-specific experts.</p>
<p>While recent surveys [<xref ref-type="bibr" rid="ref-12">12</xref>&#x2013;<xref ref-type="bibr" rid="ref-17">17</xref>] have explored the intersection of FL and LLMs, they often treat federated LLMs as a general extension of LLMs. This survey distinguishes itself by focusing on the system-level operations of LLMs in federated settings. We analyze the unresolved tension between the massive memory requirements of LLMs and the limited resources of edge devices, providing a critical comparison of solutions spanning system architecture, model fine-tuning, data security and privacy, and applications.</p>
<p>Specifically, Cheng et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] and Chen et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] provide foundational motivations but often overlook recent advancements in parameter-efficient fine-tuning and trustworthy alignment. Other studies [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>,<xref ref-type="bibr" rid="ref-17">17</xref>], offer valuable insights into edge computing and fusion strategies, respectively, but may not fully address the complex interplay between security, data heterogeneity, and retrieval-augmented generation. Ren et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] discuss LLMs broadly, yet a dedicated, granular analysis of the specific methodologies for federated LLM tuning remains necessary. <xref ref-type="table" rid="table-1">Table 1</xref> compares this survey against existing works highlighting our distinct contributions.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison of this survey with existing literature on Federated LLMs.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Reference</th>
<th>System Architecture</th>
<th>Model Fine-Tuning</th>
<th>Data Security &#x0026; Privacy</th>
<th>Applications</th>
</tr>
</thead>
<tbody>
<tr>
<td>Cheng et al. [<xref ref-type="bibr" rid="ref-12">12</xref>]</td>
<td><inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Chen et al. [<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td><inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Thakur et al. [<xref ref-type="bibr" rid="ref-14">14</xref>]</td>
<td><inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Piccialli et al. [<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Ren et al. [<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td><inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Hu et al. [<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td><inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td><bold>This Work</bold></td>
<td><inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-1fn1" fn-type="other">
<p>Note: <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mo>&#x2219;</mml:mo></mml:math></inline-formula>: Detailed coverage; <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mo>&#x2218;</mml:mo></mml:math></inline-formula>: Partial or limited coverage.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p><xref ref-type="fig" rid="fig-1">Fig. 1</xref> depicts the structure of this survey. <xref ref-type="sec" rid="s3">Section 3</xref> summarizes the advanced system architectures of federated LLMs compared with the naive centralized one. <xref ref-type="sec" rid="s4">Section 4</xref> investigates the advanced model fine-tuning methods in contrast to naive full fine-tuning. <xref ref-type="sec" rid="s5">Section 5</xref> identifies common threats to federated LLM systems and the mitigation approaches from the perspectives of privacy preservation, security and robustness, and alignment and fairness. <xref ref-type="sec" rid="s6">Section 6</xref> presents the prototypes and applications of federated LLMs in academia and industries. Finally, in <xref ref-type="sec" rid="s7">Section 7</xref>, we identify the desired properties of federated LLMs, introduce the trilemma of balancing efficiency, privacy, and utility, and outline open challenges and future directions.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Survey structure.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_79321-fig-1.tif"/>
</fig>
<p>We target at providing a comprehensive taxonomy and a critical analysis of the current federated LLM ecosystem. This survey moves beyond simple enumeration of methods to investigate the how, where, and safeguards of federated LLMs. <xref ref-type="table" rid="table-2">Table 2</xref> illustrates a unified taxonomy of federated LLMs from the perspectives of system, model, and data and articulates the common strategies, goals, key bottlenecks, and representative techniques in each perspective. Note that although <xref ref-type="table" rid="table-2">Table 2</xref> separates federated LLM research into system, model, data, and application dimensions for clarity, these dimensions are not independent in practice. In particular, privacy, security, and alignment requirements act as cross-cutting constraints that shape feasible choices in system architecture, fine-tuning strategy, and deployment settings.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>A unified taxonomy of federated LLMs, where privacy, security, and alignment act as cross-cutting constraints across system, model, and application design.</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="30mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="38mm"/> </colgroup>
<thead>
<tr>
<th>Dimension</th>
<th>Common Categories</th>
<th>Goal</th>
<th>Key Bottlenecks</th>
<th>Representative Techniques</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>System architecture</bold></td>
<td>Centralized; split FL; edge-cloud collaboration; decentralized</td>
<td>Scale training under heterogeneous resources</td>
<td>Communication, stragglers, trust</td>
<td>FedAvg variants, asynchronous FL, split FL cut-layer design, P2P aggregation, distributed ledger, federated RAG</td>
</tr>
<tr>
<td><bold>Model fine- tuning</bold></td>
<td>Full fine-tuning; PEFT; prompt tuning</td>
<td>Reduce memory and communication while keeping quality</td>
<td>Bandwidth, GPU memory</td>
<td>Federated PEFT, federated prompt engineering, knowledge distillation, in-context learning, ZO optimizers</td>
</tr>
<tr>
<td><bold>Data security and privacy</bold></td>
<td>Data leakage and privacy; data security against attacks; alignment and fairness</td>
<td>Protect confidentiality, integrity, safety</td>
<td>Data leakage, poisoning, misalignment</td>
<td>Differential privacy, secure aggregation, selective encryption, robust aggregation, federated RLHF and DPO, fairness constraints</td>
</tr>
<tr>
<td><bold>Applications</bold></td>
<td>Healthcare; industrial IoT; software engineering; text generation and legal; finance</td>
<td>Domain adaptation under regulation</td>
<td>Compliance, evaluation, deployment</td>
<td>Domain PEFT, private RAG, distillation to edge</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>To ensure a thorough and cutting-edge analysis of this rapidly evolving field, we conduct a systematic literature search using the Scopus database, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. The search strategy uses the keywords federated learning and large language model, focusing on publications published in or before 2025 to capture the most recent developments. The initial query yields 613 results. Subsequently, we apply a manual screening process based on two primary exclusion criteria. On the one hand, we exclude purely conceptual studies that present simplistic ideas without concrete methodological frameworks or validation. On the other hand, we exclude papers that use LLMs solely as auxiliary tools (e.g., for validating results generated by other models) rather than as the subject of federated integration. The screening finally yields 104 research papers. The literature review method ensures that the survey focuses exclusively on substantive methodological contributions to the intersection of FL and LLMs.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Survey method and distribution of research papers on different topics.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_79321-fig-2.tif"/>
</fig>
<p>We adopt a quantitative analytical method and classify the reviewed corpus of the 104 primary studies into six distinct categories. As illustrated in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, the distribution reveals that applications and model fine-tuning are the dominant trajectories, accounting for approximately 27% (28 papers) and 25% (26 papers) of the corpus, respectively. It indicates a dual focus within the community: expanding the practical utility of federated LLMs across domains while simultaneously addressing the computational constraints of training them. System architecture (21 papers) and data security and privacy (18 papers) form the field&#x2019;s structural backbone, collectively representing nearly 38% of the work. Conversely, the scarcity of contributions in toolkits and benchmarks (5 papers) highlights a critical gap, suggesting that while the field is innovating rapidly in methods and use cases, it currently lacks standardized evaluation frameworks and unified development platforms.</p>

<p>The main contributions of this work are as follows:<list list-type="bullet">
<list-item>
<p>We explore the system architecture and deployment strategies (<xref ref-type="sec" rid="s3">Section 3</xref>) required to support federated LLM, ranging from split FL and edge-cloud collaboration to decentralized topologies, including a discussion on advanced data strategies such as handling non-IID distributions and implementing federated retrieval-augmented generation.</p></list-item>
<list-item>
<p>We provide a detailed examination of efficient fine-tuning methodologies (<xref ref-type="sec" rid="s4">Section 4</xref>), categorizing cutting-edge techniques in federated parameter-efficient fine-tuning, prompt engineering, and memory-optimized instruction tuning. We analyze how these methods mitigate the communication and computational bottlenecks inherent to massive models.</p></list-item>
<list-item>
<p>We conduct a rigorous analysis of data security and privacy (<xref ref-type="sec" rid="s5">Section 5</xref>), synthesizing research on privacy preservation, security against poisoning attacks, and model alignment with human preferences via reinforcement learning from human feedback.</p></list-item>
<list-item>
<p>We survey diverse applications of federated LLMs across healthcare, industry, and finance (<xref ref-type="sec" rid="s6">Section 6</xref>), and outline the ongoing challenges and future research directions (<xref ref-type="sec" rid="s7">Section 7</xref>).</p></list-item>
</list></p>
</sec>
<sec id="s2">
<label>2</label>
<title>Preliminaries</title>
<p>The convergence of LLMs and FL represents a synthesis of advanced natural language processing capabilities with decentralized, privacy-preserving computation. This section establishes the foundational concepts of LLMs and FL and defines federated LLMs.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Large Language Models</title>
<p>The evolution of natural language processing has been revolutionized by the introduction of the Transformer architecture, which utilizes self-attention mechanisms to capture long-range dependencies in textual data [<xref ref-type="bibr" rid="ref-18">18</xref>]. Modern LLMs, such as GPT [<xref ref-type="bibr" rid="ref-2">2</xref>] and LLaMA [<xref ref-type="bibr" rid="ref-3">3</xref>], scale the architecture to billions of parameters, training on massive corpora to develop emergent abilities in reasoning, coding, and general knowledge generation [<xref ref-type="bibr" rid="ref-19">19</xref>]. LLMs typically require two-phase training: pre-training to learn statistical language patterns, followed by fine-tuning (or instruction tuning) to align the model with specific tasks or human preferences [<xref ref-type="bibr" rid="ref-20">20</xref>]. While pre-training establishes the model&#x2019;s knowledge base, it requires immense computational resources, often limiting it to centralized data centers equipped with high-performance GPU clusters [<xref ref-type="bibr" rid="ref-21">21</xref>]. Consequently, adapting LLMs to private, domain-specific data remains a challenge, as transferring sensitive information to a central server for fine-tuning often violates data sovereignty regulations.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Federated Learning</title>
<p>FL addresses the constraints of data isolation by enabling collaborative model training without exchanging raw data. In the most classical FedAvg algorithm [<xref ref-type="bibr" rid="ref-22">22</xref>], a central server coordinates a global model and distribute it selected clients. Each participating client <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>k</mml:mi></mml:math></inline-formula> performs local training using its local private dataset with the objective of minimizing a local loss function <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msub><mml:mi>F</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, producing a local update. The server then aggregates the clients&#x2019; updates, typically via a weighted average, to update the global model parameters <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mi>w</mml:mi></mml:math></inline-formula>. Mathematically, the objective is to minimize the global loss function <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>:<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:munder><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mrow><mml:mi>w</mml:mi></mml:mrow></mml:munder><mml:mi>F</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>K</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:msub><mml:mi>F</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>w</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>where <italic>K</italic> is the total number of clients and <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> represents the relative weight of the <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>k</mml:mi></mml:math></inline-formula>-th client, often proportional to the size of its local dataset. The FL paradigm ensures that raw data never leaves the local device, significantly reducing privacy risks. However, traditional FL faces hurdles such as statistical heterogeneity (Non-IID data), where the data distribution across clients varies significantly, leading to model drift and slow convergence [<xref ref-type="bibr" rid="ref-23">23</xref>].</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Federated Large Language Models</title>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> depicts the general pipeline of fine-tuning and personalization of LLMs in a federated setting. Federated LLMs extend the FL paradigm to the training and fine-tuning of transformer-based architectures. Unlike traditional FL, which often trains models from scratch, federated LLMs typically focus on federated fine-tuning of pre-trained LLMs. Specifically, the global model is initialized with pre-trained weights. Clients collaborate to adjust the weights (or a subset thereof) based on private instruction sets or domain-specific corpora.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>A general end-to-end federated LLM pipeline.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_79321-fig-3.tif"/>
</fig>
<p>The integration of LLMs into federated settings introduces unique system challenges not present in standard FL. The sheer size of LLM parameters, ranging from billions to trillions, imposes severe communication bottlenecks when transmitting massive model updates between clients and the central server. In addition, the memory requirements for backpropagation often exceed the hardware capabilities of edge devices or consumer-grade GPUs found in decentralized nodes. Consequently, the standard FedAvg approach is often computationally infeasible for LLMs, necessitating the adoption of parameter-efficient techniques and communication-compression strategies to make distributed training viable.</p>
<p>In federated LLMs, heterogeneity arises along at least three distinct dimensions: data, system, and tasks. Data heterogeneity refers to the discrepancies in local data distributions, label spaces, and data quality across clients, which often induce client drift and unstable convergence. System heterogeneity refers to varieties in hardware capabilities, memory, bandwidth, and availability, leading to stragglers, stale updates, and unequal participation. Task heterogeneity refers to differences in downstream tasks, personalization targets, or alignment preferences across clients, which may render a single global optimum ill-defined and lead to negative transfer under naive aggregation.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>System Architecture</title>
<p><xref ref-type="table" rid="table-3">Table 3</xref> summarizes the system-level design space of federated LLMs, focusing on where computation takes place and what information must be exchanged during training. Unlike conventional FL with small models, federated LLMs are dominated by the scale of transformer parameters and activations, which makes the choice of architecture a first-order determinant of feasibility, efficiency, and trust. We categorize existing systems into five representative architectures: (i) centralized FL, which retains the classic server-client aggregation pipeline; (ii) split FL, which partitions model layers to shift memory and compute to the server at the cost of transmitting intermediate activations; (iii) edge-cloud collaboration, which generalizes split execution via resource-aware offloading and scheduling; (iv) decentralized topologies, which remove the central coordinator to improve resilience and reduce trust assumptions; and (v) hybrid designs that combine the first four primitives. For each category, <xref ref-type="table" rid="table-3">Table 3</xref> highlights the principal communication object, practical advantages, and key limitations, providing a concise guide for selecting architectures under different resource, privacy, and deployment constraints.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>System architecture taxonomy for federated LLMs and major trade-offs.</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="30mm"/>
<col align="center" width="30mm"/>
<col align="center" width="30mm"/>
<col align="center" width="30mm"/> </colgroup>
<thead>
<tr>
<th>Architecture</th>
<th>Where LLM Runs</th>
<th>Communication Object</th>
<th>Advantages</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Centralized FL</bold></td>
<td>Client trains locally; server aggregates</td>
<td>Gradients/weights/ adapter deltas</td>
<td>Simple; strong coordination; mature tooling</td>
<td>Bandwidth heavy for LLMs; stragglers; single point of failure</td>
</tr>
<tr>
<td><bold>Split FL</bold></td>
<td>Client runs early layers; server runs later layers</td>
<td>Activations and gradients at the cut layer</td>
<td>Enables training when clients cannot host the full model</td>
<td>Activation leakage risk; high uplink usage; cut-layer tuning complexity</td>
</tr>
<tr>
<td><bold>Edge-cloud collaboration</bold></td>
<td>Dynamic partitioning/offloading across edge and cloud</td>
<td>Mixed (deltas, activations, partial states)</td>
<td>Resource-aware scheduling; better latency/throughput</td>
<td>Orchestration complexity; privacy boundary management</td>
</tr>
<tr>
<td><bold>Decentralized</bold></td>
<td>Peers exchange/validate updates without a central server</td>
<td>Peer updates and ledger proofs/records</td>
<td>Removes central trust; resilient; incentives possible</td>
<td>Consensus overhead; aggregation quality control; incentive design</td>
</tr>
<tr>
<td><bold>Hybrid</bold></td>
<td>Combine above (e.g., split FL, asynchronous FL, and PEFT)</td>
<td>Task-dependent</td>
<td>Integration of advantages above</td>
<td>Hard to analyze; evaluation and reproducibility challenges</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>From the perspective of heterogeneity, the architectural choices primarily respond to system heterogeneity, i.e., variation in client resources, connectivity, and availability. Although architectural decisions also interact with privacy and data diversity, their primary role is to ensure end-to-end training feasibility under uneven computational and communication capabilities. In contrast, data heterogeneity is discussed in <xref ref-type="sec" rid="s3_4_1">Section 3.4.1</xref>, while task heterogeneity becomes especially visible in personalized fine-tuning and multi-task adaptation settings discussed in <xref ref-type="sec" rid="s4">Section 4</xref>.</p>
<p>Beyond efficiency and scalability, architectural choices in federated LLMs also determine the system&#x2019;s trust model and attack surface. For instance, centralized FL concentrates coordination but creates a single point of failure, split FL alleviates client memory limits at the cost of activation leakage risk, and decentralized designs reduce central trust assumptions while introducing new validation and consensus challenges.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Split Federated Learning</title>
<p>The prohibitive memory requirements of LLMs often render standard FL infeasible on edge devices with limited resources. Split FL addresses the bottleneck by partitioning the model architecture between the client and server. In split FL, the client executes the initial layers (the head) to generate intermediate activations, which are then transmitted to the server for forward propagation through the remaining layers (the tail) [<xref ref-type="bibr" rid="ref-24">24</xref>]. Gradients flow in reverse during backpropagation. The structural division allows clients to train massive models while holding only a fraction of the parameters locally.</p>
<p>Implementing split FL for LLMs requires robust frameworks that can handle the high communication overhead of transmitting activation maps. FedsLLM [<xref ref-type="bibr" rid="ref-25">25</xref>] introduces a parallelized split FL architecture specifically optimized for communication networks. By enabling parallel training across multiple clients and synchronizing the split-layer boundaries, the framework mitigates the straggler effect common in sequential split learning. FedsLLM significantly reduces the computational load on edge devices compared to full-model FL, although it introduces a heavy dependency on uplink bandwidth.</p>
<p>VFLAIR-LLM [<xref ref-type="bibr" rid="ref-26">26</xref>] is proposed to rigorously evaluate different split federated LLM architectures. It provides a comprehensive benchmark suite. VFLAIR-LLM elucidates the trade-offs between cut-layer selection, communication latency, and model performance, and serves as a critical tool for system designers, offering metrics that quantify how different splitting strategies affect the convergence rate and resource consumption of various LLM backbones.</p>
<p>While architectural splitting solves memory constraints, it introduces optimization challenges, particularly when data distributions across clients are non-IID. The separation of layers can decouple the learning of low-level features (client-side) from high-level semantic reasoning (server-side).</p>
<p>To counter potential degradation in generalization capability, recent research has integrated advanced minimization techniques into the split FL workflow. Tan et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] propose incorporating sharpness-aware minimization into the local client updates. By seeking parameters that lie in neighborhoods of uniformly low loss rather than sharp minima, the method improves the model&#x2019;s robustness to heterogeneous data. The integration ensures that the split configuration does not compromise the global model&#x2019;s ability to generalize across diverse user prompts.</p>
<p>Split FL is frequently cited as a privacy-preserving solution because raw data remains local. However, the transmission of intermediate activations creates a new attack surface. A critical analysis [<xref ref-type="bibr" rid="ref-28">28</xref>] challenges the assumption of inherent security. In particular, inversion attacks can reconstruct original inputs from cut-layer activations, especially in the context of LLMs with high semantic density. The finding necessitates the integration of differential privacy or activation compression mechanisms to obfuscate the transmitted signals.</p>
<p>Furthermore, the reliance on continuous communication makes split FL vulnerable to physical-layer disruptions. R-SFLLM [<xref ref-type="bibr" rid="ref-29">29</xref>] addresses the issue by proposing a jamming-resilient framework. Recognizing that wireless channels are susceptible to interference, the authors design a robust transmission protocol that maintains training stability even under active jamming attacks. R-SFLLM ensures that the collaborative fine-tuning process remains viable in hostile or unstable network environments.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Edge-Cloud Collaboration</title>
<p>The deployment of LLM within federated settings necessitates a paradigm shift from simple parameter aggregation to complex edge-cloud orchestration. Unlike traditional FL, where models are small enough for trivial on-device processing, LLMs impose severe computational and memory demands. Consequently, recent literature focuses on intelligent scheduling, resource-aware offloading, and collaborative architectures that bridge the gap between high-capacity cloud servers and resource-constrained edge devices.</p>
<p>Standard FedAvg suffers from the straggler effect, where the global training speed is bottlenecked by the slowest device. The straggler issue is exacerbated in federated LLM due to the heterogeneity of edge hardware. To address the issue, Tri-AFLLM [<xref ref-type="bibr" rid="ref-30">30</xref>] introduces a resource-efficient adaptive framework. By abandoning synchronous lock-step updates in favor of an asynchronous protocol, the system allows faster clients to contribute more frequently while slower nodes update partially. Tri-AFLLM significantly improves convergence speed without idling powerful resources.</p>
<p>Beyond timing, the qualitative match between a client&#x2019;s data and the model&#x2019;s objective is crucial. FedCLLM [<xref ref-type="bibr" rid="ref-31">31</xref>] shows that random client selection is inefficient for LLM fine-tuning. Instead, it utilizes domain descriptions to match clients with specific downstream tasks. By filtering participants based on the semantic relevance of local data, the framework ensures that the global model aggregates high-value updates, reducing communication rounds and improving task-specific performance.</p>
<p>Once participants are selected, orchestrating the compute resources becomes important. LTQA [<xref ref-type="bibr" rid="ref-32">32</xref>] proposes a delay-optimization strategy. It continuously monitors network latency and computational throughput, dynamically assigning training loads to nodes that minimize the overall system delay.</p>
<p>Software optimization alone is often inadequate to bridge the resource gap for LLMs. Recent approaches have begun to exploit specialized hardware at the edge. Huang et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] integrate Embedded Data Processing Units (DPUs) into the workflow. By offloading specific tensor operations and data preprocessing tasks to DPUs, the main CPU/GPU is freed for core model updates, effectively expanding the compute envelope of edge devices.</p>
<p>For environments where individual devices cannot hold even a quantized model, DisLLM [<xref ref-type="bibr" rid="ref-34">34</xref>] proposes a distributed inference and training architecture. The framework partitions the LLM across a mesh of resource-constrained devices, treating the edge network as a single cohesive computer. While DisLLM enables deploying larger models, it requires rigorous privacy assurances to prevent data leakage between collaborating nodes.</p>
<p>To unify the methods above, comprehensive frameworks are required. MPCTF [<xref ref-type="bibr" rid="ref-35">35</xref>] establishes a multi-party collaborative training protocol that standardizes the interaction between data owners, compute providers, and model architects. The abstraction layer simplifies the setup of decentralized LLM training.</p>
<p>Complementing the training phase, FoRA [<xref ref-type="bibr" rid="ref-36">36</xref>] focuses on efficiently propagating knowledge from the cloud to the edge. It optimizes the fine-tuning process for on-device LLMs by selectively transferring parameters that yield the highest accuracy gains, thereby minimizing bandwidth consumption during the downlink phase. Meanwhile, ensuring the federated LLM systems operate securely in production can be addressed by federated data modeling [<xref ref-type="bibr" rid="ref-37">37</xref>], which outlines cloud-native architectures for deploying collaborative models while adhering to strict security compliance standards.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Decentralized Approaches</title>
<p>Centralized orchestration in federated LLMs often suffers from a single point of failure and limited scalability. Furthermore, the dependence on a central server raises concerns regarding censorship and trust. To mitigate the risks, the architecture of federated LLM is increasingly moving towards decentralized, peer-to-peer topologies, often underpinned by blockchain technology to ensure integrity and incentivize participation.</p>
<p>In environments lacking a trusted central authority, blockchain ledgers provide an immutable record of model updates. PureLLM [<xref ref-type="bibr" rid="ref-38">38</xref>] introduces a blockchain-driven decentralized framework specifically for personalized FL. By removing the central aggregator, PureLLM allows devices to exchange updates directly via a peer-to-peer mesh. The blockchain consensus mechanism validates these updates, filtering out malicious contributions before they are assimilated into the local models. The structure not only enhances robustness against poisoning attacks but also improves resource efficiency by allowing nodes to selectively assimilate knowledge relevant to specific tasks.</p>
<p>A critical challenge in decentralized federated LLM is the free-rider problem, where participants obtains the global model with limited or no contributions. DISM [<xref ref-type="bibr" rid="ref-39">39</xref>] addresses the free-rider problem by embedding a reward system within the blockchain protocols. Smart contracts automatically dispense tokens or reputation marks to clients based on the quality and volume of data contributions. Such an economic layer is essential for sustaining long-term collaborative fine-tuning, because the computational cost of training LLMs is too high for altruistic participation alone.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Advanced Data Strategies</title>
<p>The utility of federated LLMs relies heavily on the quality of distributed data and how the data is used. Unlike centralized training, where data is curated and shuffled, federated environments suffer from extreme statistical heterogeneity (Non-IID data) and varying data quality. Furthermore, the static nature of parametric knowledge in LLMs conflicts with the dynamic information available at the edge. Hence, we explore strategies to mitigate data heterogeneity through advanced filtering and distillation, as well as methods to augment generation using distributed knowledge bases.</p>
<sec id="s3_4_1">
<label>3.4.1</label>
<title>Handling Non-IID Data</title>
<p>Data heterogeneity in federated LLMs refers to differences in local data distributions across clients, including concept drift, domain shift, task imbalance, and quality variance. The main technical effect is to increase divergence between local and global optimization trajectories, which can slow convergence, destabilize aggregation, and reduce final generalization performance. In contrast to system heterogeneity, which affects training speed and participation, data heterogeneity directly influences the statistical consistency of the learned global model. Data heterogeneity in federated LLM manifests in two primary forms: distribution shifts (concept drift) and quality variance. The standard FedAvg algorithm often fails when client datasets diverge significantly in task composition or noise levels.</p>
<p>Not all local data contributes positively to the global model. Low-quality or irrelevant samples can degrade performance and slow convergence. To address this, FedDDF [<xref ref-type="bibr" rid="ref-40">40</xref>] introduces a mechanism to assess data utility during training. By dynamically filtering out samples with high loss variance or low alignment with the global objective, the system ensures that the model learns only from high-value local interactions.</p>
<p>A related challenge is the scarcity of labeled instruction data on edge devices. Clients typically possess abundant unstructured text but lack the instruction-response pairs required for fine-tuning. FedIT-U2S [<xref ref-type="bibr" rid="ref-41">41</xref>] proposes an automated pipeline where an auxiliary teacher model synthesizes instructions from raw local text. It allows the federated network to utilize vast amounts of previously unusable data for instruction tuning without manual annotation.</p>
<p>When clients perform fundamentally different tasks, forcing a single global model to master all of them simultaneously can lead to negative transfer. MIRA [<xref ref-type="bibr" rid="ref-42">42</xref>] frames the problem as federated multi-task learning. Rather than aggregating all weights equally, MIRA employs a routing mechanism that allows the global model to specialize parameters for distinct tasks across client clusters. It preserves the unique capabilities required by specific edge cases while maintaining a shared knowledge base.</p>
<p>Deploying full-scale LLMs on resource-constrained clients is often infeasible. Knowledge distillation has been considered a potent solution to close the gap between large server-side models and smaller client-side networks. FedBiOT [<xref ref-type="bibr" rid="ref-43">43</xref>] introduces a bilevel optimization framework in which clients perform local fine-tuning without requiring access to the full model. Through a distillation process, the client optimizes a lightweight adapter or compressed model, which is then synchronized with the server. FedBiOT reduces communication costs significantly while retaining the performance benefits of larger architectures.</p>
<p>Similarly, FedBridgeICL [<xref ref-type="bibr" rid="ref-44">44</xref>] explores the synergy between small and large models via in-context learning. Instead of traditional gradient updates, FedBridgeICL uses the large server model to generate high-quality context vectors or demonstrations. The vectors or demonstrations are transmitted to smaller client models to guide inference. Such a bridging approach allows small edge models to emulate the reasoning capabilities of larger counterparts without incurring the computational cost of full parameter synchronization.</p>
</sec>
<sec id="s3_4_2">
<label>3.4.2</label>
<title>Federated Retrieval-Augmented Generation</title>
<p>Parametric knowledge in LLMs is prone to hallucinations and quickly becomes outdated. Retrieval-Augmented Generation (RAG) mitigates the issue by fetching relevant context from an external database. Federated RAG refers to the process of responding to user prompts by fusing local private knowledge with global shared knowledge (as illustrated in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>).</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Workflow of federated retrieval-augmented generation.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_79321-fig-4.tif"/>
</fig>
<p>DF-RAG [<xref ref-type="bibr" rid="ref-45">45</xref>] proposes a framework specifically designed for collaborative environments like healthcare. First, a local retrieval module accesses private patient records on the client device to answer specific queries. Second, a privacy-preserving global retrieval module accesses a shared index of medical knowledge contributed by other institutions. The separation ensures that sensitive local data (e.g., patient history) never leaves the device, while general medical insights are shared. By aggregating retrieval results rather than raw data, DF-RAG enables the LLM to generate informed, personalized, and globally consistent responses.</p>
<p>Federated RAG introduces additional privacy risks beyond those of standard federated fine-tuning because leakage may occur throughout the retrieval pipeline. In particular, sensitive information may be exposed through index leakage (e.g., embeddings, metadata, or index structure), query leakage (user intent or private prompts), retrieval-result leakage (returned passages, scores, or provenance), and update leakage from retriever or index optimization. The leakage channels are tightly coupled with retrieval quality: stronger privacy protection through obfuscation, restricted sharing, or encrypted retrieval may reduce recall, ranking precision, or latency performance. Hence, federated RAG should be evaluated not only by generation utility but also by the joint privacy-retrieval-effectiveness trade-off.</p>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Model Fine-Tuning</title>
<p><xref ref-type="table" rid="table-4">Table 4</xref> organizes the efficiency-centric adaptation strategies that make federated training of LLMs practical under tight client constraints. Because end devices and cross-silo participants often lack the memory, compute, and uplink bandwidth required for full-parameter backpropagation, federated LLM research increasingly focuses on shrinking the parameters to be trained, reducing model updates and communication overhead, and accommodating heterogeneous hardware. We group existing approaches into six method families: full fine-tuning, parameter-efficient fine-tuning (PEFT), prompt tuning, zeroth-order (gradient-free) tuning, distillation and bridging, and quantization-aware FL. Furthermore, we summarize the training target, client-side requirements, and the resulting communication cost for each method. The taxonomy serves as a conceptual decision aid for selecting federated fine-tuning approaches under different resource, privacy, and deployment constraints. We stress that the methods are extremely sensitive to hyperparameter settings and system conditions, including privacy considerations, quantization level, client participation, and data heterogeneity. For instance, PEFT and prompt tuning are often preferred when bandwidth and memory are limited, while distillation and quantization are attractive for deployment-oriented scenarios where the goal is to produce smaller or lower-precision models without moving raw data off-client. Meanwhile, note that fine-tuning methods are not chosen solely for resource efficiency. The methods also determine which parts of the model and intermediate states are exposed during FL, and what security assumptions and defense mechanisms are feasible.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Taxonomy of efficient fine-tuning methods for federated LLMs.</title>
</caption>
<table>
<colgroup>
<col align="center" width="28mm"/>
<col align="center" width="28mm"/>
<col align="center" width="28mm"/>
<col align="center" width="25mm"/>
<col align="center" width="35mm"/> </colgroup>
<thead>
<tr>
<th>Method Family</th>
<th>What Is Trained</th>
<th>Client Requirements</th>
<th>Communication Cost</th>
<th>Notes (Typical Use Cases)</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Full fine-tuning</bold></td>
<td>All parameters</td>
<td>Large GPU memory; stable connectivity</td>
<td>Very high</td>
<td>Rare for edge; mostly for datacenters or small LLMs</td>
</tr>
<tr>
<td><bold>PEFT</bold></td>
<td>Low-rank matrices or adapters; backbone frozen</td>
<td>Moderate memory; gradient access</td>
<td>Low to medium</td>
<td>Default choice in federated LLM; supports personalization and heterogeneity</td>
</tr>
<tr>
<td><bold>Prompt tuning</bold></td>
<td>Prompt vectors or tokens; model frozen</td>
<td>Low memory; sometimes gradient-free possible</td>
<td>Very low</td>
<td>Works well when the model is black-box or the devices are weak</td>
</tr>
<tr>
<td><bold>Zeroth-order tuning</bold></td>
<td>No backprop graph; gradient estimated from probes</td>
<td>Very low memory; more forward passes</td>
<td>Low to medium</td>
<td>Good for tight-memory clients; can be noisy or slow to converge</td>
</tr>
<tr>
<td><bold>Distillation and bridging</bold></td>
<td>Student (small) model or adapters learn from teacher outputs</td>
<td>Mostly inference on the teacher; training on the student</td>
<td>Low (often logits or demos)</td>
<td>Edge deployment; compress knowledge; security needs auditing</td>
</tr>
<tr>
<td><bold>Quantization -aware FL</bold></td>
<td>Low-bit weights or adapters (heterogeneous precision)</td>
<td>Device-specific precision support</td>
<td>Low</td>
<td>Addresses heterogeneity; aggregation across precisions is non-trivial</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s4_1">
<label>4.1</label>
<title>Federated Parameter-Efficient Fine-Tuning</title>
<p>Federated LLMs faces a critical bottleneck: the prohibitive cost of full-parameter fine-tuning. With model sizes ranging from billions to trillions of parameters, transmitting full gradient updates saturates communication bandwidth and overwhelms the memory capacities of edge devices. Federated PEFT avoids transmitting full gradient updates by freezing the pre-trained backbone and updating only a small subset of parameters or additional adapter modules [<xref ref-type="bibr" rid="ref-46">46</xref>]. Among different strategies, Low-Rank Adaptation (LoRA) [<xref ref-type="bibr" rid="ref-47">47</xref>] is regarded as the de facto standard, enabling clients to train low-rank matrices that approximate weight updates. Recent literature has expanded beyond basic LoRA implementations to address specific federated challenges, including system heterogeneity, communication constraints, and data personalization.</p>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Communication and Resource Optimization</title>
<p>Standard implementations of PEFT often fail to consider the stochastic characteristics of wireless edge networks. Wireless channels introduce latency and packet loss, necessitating joint optimization of learning and transmission. AirFL-LoRA [<xref ref-type="bibr" rid="ref-48">48</xref>] formulates an optimization problem that balances the computation rank with wireless resource allocation. By adjusting the rank of LoRA adapters based on channel quality, the system maximizes convergence speed while adhering to strict energy budgets.</p>
<p>Sustainability has also become a primary objective. The carbon footprint of training LLMs is substantial, and federated settings exacerbate the sustainability concern because redundant local computations are required. Iftikhar et al. [<xref ref-type="bibr" rid="ref-49">49</xref>] illustrate that federated PEFT greatly saves energy consumption in comparison with centralized training by minimizing data movement and leveraging low-power edge processors. Furthermore, Jiang et al. [<xref ref-type="bibr" rid="ref-50">50</xref>] establish baseline protocols for reducing the trainable parameter space, proving that massive reductions in communication overhead can be achieved with negligible degradation in downstream task performance.</p>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Dynamic and Adaptive Mechanisms</title>
<p>Static adapter configurations often yield sub-optimal results because different layers of an LLM contribute unequally to task adaptation [<xref ref-type="bibr" rid="ref-51">51</xref>]. DynamicFedPEFT [<xref ref-type="bibr" rid="ref-52">52</xref>] introduces a mechanism to dynamically adjust the trainable parameters during the training process. Rather than fixing the rank or the specific modules beforehand, the framework monitors gradient norms to allocate trainable parameters to the most sensitive layers, thereby accelerating convergence.</p>
<p>Similarly, not all parameters within a LoRA adapter are equally important. The adaptive importance-aware LoRA approach [<xref ref-type="bibr" rid="ref-53">53</xref>] integrates an importance scoring mechanism. Local clients prune less significant ranks during the update phase, transmitting only the most critical weight changes to the server. The method serves a dual purpose: it acts as a compression scheme to reduce uplink traffic and prevents overfitting by regularizing the adaptation process on local datasets.</p>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>System Heterogeneity and Aggregation Strategies</title>
<p>A pervasive challenge in FL is system heterogeneity, where clients possess varying computational capabilities. Enforcing a uniform LoRA rank across all clients forces the system to operate at the speed of the slowest device [<xref ref-type="bibr" rid="ref-54">54</xref>]. To mitigate the issue, Ning et al. [<xref ref-type="bibr" rid="ref-55">55</xref>] permit clients to train adapters with ranks proportional to local resources. However, aggregating matrices of different dimensions introduces structural errors. To this end, an error-compensated aggregation protocol is proposed that aligns diverse local updates into a coherent global model without discarding information from weaker clients.</p>
<p>Furthermore, Zhu et al. [<xref ref-type="bibr" rid="ref-56">56</xref>] focus on the algorithmic stability of aggregation. By refining the update rules, the framework dampens the noise introduced by non-IID data distributions, ensuring that the global aggregation of low-rank matrices remains stable even when local updates diverge significantly.</p>
<p>From a theoretical perspective, the stability of federated LoRA aggregation depends not only on update magnitude but also on the geometric compatibility of client-specific low-rank subspaces. When clients adopt heterogeneous ranks or use different layers under non-IID data, their low-rank updates may span mismatched directions, leading naive averaging to introduce projection error and amplify client drift. Existing studies suggest that aggregation becomes more stable when the principal adaptation subspaces are approximately aligned and when update norms are appropriately normalized or error-compensated [<xref ref-type="bibr" rid="ref-56">56</xref>]. However, a general theory covering heterogeneous LoRA ranks, partial participation, and strongly non-IID settings remains incomplete. We therefore view current results as an important first step rather than a complete characterization of the stability of federated PEFT.</p>
<p>Finally, the efficacy of federated PEFT relies heavily on which clients participate in training. Solat and Lee [<xref ref-type="bibr" rid="ref-57">57</xref>] argue that random selection is inefficient for LLM adaptation. The proposed strategy evaluates potential participants based on both computational readiness and informational value of local data, ensuring that communication rounds are utilized by the most impactful contributors.</p>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Personalization</title>
<p>While the global model aims for generalization, local clients often require personalization. FedALoRA [<xref ref-type="bibr" rid="ref-58">58</xref>] proposes an adaptive local aggregation scheme. Instead of simply overwriting the local adapter with the global average, the method computes a weighted combination, allowing the local model to retain knowledge specific to the user&#x2019;s data distribution while benefiting from global knowledge.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Federated Prompt Engineering</title>
<p>Federated PEFT reduces the computational burden by updating a subset of model parameters; however, it still requires access to the model&#x2019;s gradients and internal weights. Such a requirement poses a barrier for clients with severe resource constraints or when the LLM is deployed as a black-box service. Federated prompt engineering addresses these limitations by optimizing the input space rather than the model space [<xref ref-type="bibr" rid="ref-59">59</xref>]. By learning optimal discrete tokens or continuous embeddings, federated prompt engineering enables clients to steer the global model&#x2019;s behavior with minimal communication overhead.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Continuous Soft Prompt Optimization</title>
<p>Soft prompting involves prepending learnable continuous vectors to the input sequence. The vectors are optimized via backpropagation while keeping the LLM frozen. In the federated context, soft prompting allows for extreme parameter efficiency, as only the small prompt vectors need to be aggregated.</p>
<p>Recent applications have extended the soft prompting technique beyond traditional natural language processing tasks. For instance, the FPTuning-LLM framework [<xref ref-type="bibr" rid="ref-60">60</xref>] adapts LLMs for time-series forecasting in the hotel industry. By treating historical booking data as textual sequences and applying soft prompt tuning, the system leverages LLMs&#x2019; semantic reasoning to predict future demand without exposing sensitive commercial data. FPTuning-LLM shows that learnable prompts can effectively bridge the modality gap between numerical time-series data and pre-trained linguistic representations.</p>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Discrete Prompting and Synthetic Augmentation</title>
<p>Unlike soft prompts, which are continuous embeddings, discrete prompts consist of human-readable tokens. Optimizing these tokens is challenging due to the non-differentiable nature of discrete text. However, discrete prompts offer better interpretability and transferability.</p>
<p>To address data scarcity among local clients, Tanimura et al. [<xref ref-type="bibr" rid="ref-61">61</xref>] introduce a mechanism that uses synthetic examples. The framework augments local datasets with synthetically generated samples, allowing the prompt tuner to converge more robustly. By mixing real and synthetic data, the system mitigates the risk of overfitting to sparse local distributions while maintaining the privacy guarantees inherent to FL.</p>
</sec>
<sec id="s4_2_3">
<label>4.2.3</label>
<title>Black-Box and Edge-Centric Adaptation</title>
<p>In many real-world deployments, clients interact with LLMs via APIs (known as Model-as-a-Service) and do not have access to gradients. The model-as-a-service paradigm necessitates the use of derivative-free optimization strategies. FebBPT [<xref ref-type="bibr" rid="ref-62">62</xref>] targets edge environments where computational power is severely limited. Instead of backpropagating errors, the system employs evolution strategies or reinforcement learning signals to iteratively refine prompts based on the model&#x2019;s output. FebBPT shifts the computational load from gradient calculation to inference, enabling the deployment of sophisticated prompt tuning on lightweight edge devices.</p>
</sec>
<sec id="s4_2_4">
<label>4.2.4</label>
<title>Reasoning and Scheduling Efficiency</title>
<p>Beyond simple task adaptation, prompt engineering in federated settings is increasingly focused on enhancing LLMs&#x2019; reasoning capabilities and optimizing system throughput.</p>
<p>Liu et al. [<xref ref-type="bibr" rid="ref-63">63</xref>] explore aggregating reasoning paths. Rather than merely averaging prompt vectors, the approach encourages clients to share successful Chain-of-Thought (CoT) templates. The global model thereby learns to structure its reasoning more effectively, leading to improved accuracy on complex query-answering tasks.</p>
<p>Simultaneously, the efficiency of processing these prompts is critical. FedLLM-PPS [<xref ref-type="bibr" rid="ref-64">64</xref>] addresses the latency bottlenecks associated with handling multiple prompt requests. A parallel scheduling algorithm is proposed to optimize the order and batching of prompt evaluations across the federated network. It ensures that the computational resources of participating clients are used to their fullest, reducing the overall time-to-convergence of the global prompt model.</p>
</sec>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Quantization and Zeroth-Order Optimization</title>
<p>Training LLMs within a federated ecosystem imposes severe memory and communication constraints [<xref ref-type="bibr" rid="ref-65">65</xref>]. Standard backpropagation is often infeasible on consumer-grade edge devices because it requires storing activation maps and optimizer states. Consequently, the research community has pivoted toward advanced optimization paradigms that circumvent full-precision gradient computation. The techniques include Zeroth-Order optimization, heterogeneous quantization, and hybrid gradient strategies.</p>
<sec id="s4_3_1">
<label>4.3.1</label>
<title>Zeroth-Order Optimization</title>
<p>Zeroth-Order optimization has emerged as a compelling alternative to First-Order methods. By approximating gradients through forward passes and random perturbations, Zeroth-Order methods eliminate the need to store the computation graph, thereby significantly reducing memory footprints.</p>
<p>Recent works have sought to stabilize Zeroth-Order convergence in federated settings. FedAdamZO [<xref ref-type="bibr" rid="ref-66">66</xref>] integrates adaptive momentum into the derivative-free process. FedAdamZO shows that combining Adam-style momentum with zeroth-order estimators helps overcome the high variance typically associated with random gradient approximations, making it suitable for memory-constrained fine-tuning. Besides algorithmic innovation, theoretical foundations have been strengthened by studies such as FedMeZO [<xref ref-type="bibr" rid="ref-67">67</xref>]. In particular, existing analyses derive convergence bounds for federated zeroth-order tuning under non-IID data by assuming smooth objectives, bounded estimator variance, and controlled client heterogeneity. The results are important because they show that derivative-free tuning can remain convergent even when local data distributions are biased. At the same time, the guarantees are still conditional on assumptions whose validity may weaken in practical federated LLM settings with heavy-tailed updates, partial participation, and highly heterogeneous tasks. Therefore, current theory provides a useful baseline justification for zeroth-order federated tuning, but its extension to more realistic large-scale LLM regimes remains an open problem.</p>
<p>Beyond efficiency, derivative-free methods offer inherent privacy advantages. FedDPZO [<xref ref-type="bibr" rid="ref-68">68</xref>] highlights that transmitting perturbed loss values or weights, rather than explicit gradients, reduces the attack surface for gradient leakage exploits. FedDPZO aligns well with the privacy-preservation mandate of FL while maintaining competitive performance on downstream tasks.</p>
</sec>
<sec id="s4_3_2">
<label>4.3.2</label>
<title>Heterogeneous Quantization</title>
<p>In practical deployments, client devices possess diverse hardware capabilities, ranging from high-end workstations to mobile phones. Uniform optimization strategies often fail to accommodate the disparity.</p>
<p>To address system heterogeneity, FAH-QLoRA [<xref ref-type="bibr" rid="ref-69">69</xref>] proposes a flexible framework. Clients with limited resources participate by training heavily quantized models (e.g., 4-bit), while capable clients utilize higher precision (e.g., 8- or 16-bit). The server aggregates the heterogeneous updates into a unified global model. FAH-QLoRA combines the quantization technique with LoRA to ensure that no participant is excluded due to hardware limitations, effectively maximizing the available training data across the network.</p>
</sec>
<sec id="s4_3_3">
<label>4.3.3</label>
<title>Hybrid Strategies</title>
<p>While Zeroth-Order and quantization reduce resource demands, First-Order methods generally yield faster convergence. Researchers have thus developed hybrid, accelerated schemes to balance efficiency and training speed.</p>
<p>FedHO [<xref ref-type="bibr" rid="ref-70">70</xref>] introduces a memory-efficient protocol via hybrid gradient computation. By strategically alternating between precise gradient calculations and approximated updates, or by offloading specific computational chunks, the framework reduces the peak memory usage on local devices without sacrificing the accuracy benefits of gradient-based learning.</p>
<p>Furthermore, the choice of optimizer plays a critical role in instruction tuning. FEDNPAIT [<xref ref-type="bibr" rid="ref-71">71</xref>] investigates the application of Nesterov-accelerated Adaptive Moment Estimation and its partially adaptive variant in federated environments. The study reveals that advanced momentum-based optimizers can significantly accelerate convergence for instruction-following tasks compared to standard SGD or FedAvg, particularly in the complex loss landscapes of LLMs.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Data Security and Privacy</title>
<p><xref ref-type="table" rid="table-5">Table 5</xref> summarizes the security- and privacy-critical threats for federated LLMs and the corresponding defense mechanisms commonly adopted in the literature. Although FL avoids the direct centralization of raw training data, federated LLM pipelines still expose multiple attack surfaces, including gradients and adapter updates, split-learning activations, model outputs accessible to queriers, and even the underlying communication channel, that can leak sensitive information or compromise model integrity. Moreover, the scale and memorization capacity of LLMs amplify risks, while heterogeneous and partially trusted participants create opportunities for poisoning and backdoor insertion. In this section, we organize threats by the attack surface and downstream impact, then map them to representative defenses. The final column highlights unresolved challenges, particularly the utility-privacy trade-off at LLM scale, the cost of robust validation, and the difficulty of auditing fairness and alignment when sensitive attributes remain local, motivating the open problems and future directions in <xref ref-type="sec" rid="s7">Section 7</xref>. Importantly, the data security and privacy issues concerned are not independent of the technical choices of system architecture and fine-tuning methods. Instead, the issues emerge from and constrain the system architecture and fine-tuning mechanisms adopted by federated LLM systems.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Threat-defense taxonomy for data security and privacy in federated LLMs.</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="28mm"/>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/> </colgroup>
<thead>
<tr>
<th>Threat</th>
<th>Attack Surface</th>
<th>Impact</th>
<th>Common Defenses</th>
<th>Open Issues</th>
</tr>
</thead>
<tbody>
<tr>
<td>Gradient and update leakage</td>
<td>Gradients, adapter deltas, activations (split FL)</td>
<td>Reconstruction of private text or personally identifiable information</td>
<td>DP, secure aggregation, selective encryption, activation protection</td>
<td>Utility loss; tight privacy accounting for PEFT or prompting</td>
</tr>
<tr>
<td>Membership inference</td>
<td>Model outputs and representations</td>
<td>Whether a record/client participated</td>
<td>DP, query throttling, auditing</td>
<td>Hard for LLMs with memorization; eval standards lacking</td>
</tr>
<tr>
<td>Poisoning and backdoors</td>
<td>Malicious client updates; distillation channels</td>
<td>Targeted misbehavior; integrity loss</td>
<td>Robust aggregation, anomaly detection, update validation, attestation</td>
<td>Adaptive attackers; expensive validation at LLM scale</td>
</tr>
<tr>
<td>Wireless disruption and jamming</td>
<td>Physical layer or packet corruption</td>
<td>Training instability; degraded convergence</td>
<td>Channel-aware aggregation; redundancy; scheduling</td>
<td>Joint design of communications and learning is still immature</td>
</tr>
<tr>
<td>Misalignment and bias</td>
<td>Preference data; prompts; aggregation policies</td>
<td>Harmful or unfair outputs</td>
<td>Federated RLHF and DPO, fairness constraints, prompt screening</td>
<td>Pluralistic values conflict; fairness auditing with local-only attributes</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s5_1">
<label>5.1</label>
<title>Privacy Preservation</title>
<p>While FL fundamentally mitigates privacy risks by retaining raw data on local devices, integrating LLMs introduces novel vulnerabilities. The vast parameter space of LLMs allows for the unintended memorization of training data [<xref ref-type="bibr" rid="ref-72">72</xref>], and the exchange of high-dimensional gradients or parameter updates can be exploited to reconstruct original inputs [<xref ref-type="bibr" rid="ref-73">73</xref>]. Consequently, privacy mechanisms in federated LLM must evolve beyond standard aggregation to address specific threats ranging from sensitive data identification to cross-cloud leakage.</p>
<p>Effective privacy preservation begins before the training process initiates. Traditional FL assumes that keeping data local is sufficient, yet it overlooks the risk that models may inadvertently learn and regurgitate personally identifiable information. FedAPILLM [<xref ref-type="bibr" rid="ref-74">74</xref>] proposes utilizing the federated LLM framework itself to detect vulnerabilities. By training a federated model to recognize sensitive fields within API structures, the system can automatically flag or redact such information in real time. FedAPILLM proactively ensures that the data fed into the fine-tuning process is sanitized, thereby reducing the surface area for potential privacy breaches during subsequent model interactions.</p>
<p>The gradients exchanged during LLM fine-tuning contain significant information about the local batch data. Adversaries can employ gradient inversion techniques to reconstruct the original text. A recent study [<xref ref-type="bibr" rid="ref-75">75</xref>] highlights that the risk is particularly acute in LLMs due to the semantic richness of the text data. The authors advocate advanced noise injection mechanisms that go beyond standard Differential Privacy (DP) to address gradient inversion attacks. By analyzing the correlation between gradient sparsity and information leakage, the proposed methods selectively perturb updates to maximize privacy while preserving linguistic quality.</p>
<p>Applying heavy cryptographic protocols or uniform noise to billions of parameters is computationally prohibitive and detrimental to model convergence. Pan and Wu [<xref ref-type="bibr" rid="ref-76">76</xref>] address the efficiency bottleneck. The core premise is that not all model parameters contribute equally to privacy leakage. By identifying and encrypting only the most sensitive subsets of parameters (often those associated with rare tokens or specific attention heads), the system significantly reduces computational overhead while maintaining robust protection levels.</p>
<p>Besides selective encryption, sampling strategies offer a statistical shield. FCLM [<xref ref-type="bibr" rid="ref-77">77</xref>] introduces a method designed for non-IID environments. Instead of aggregating updates from all clients or random subsets, the system clusters clients based on similarities in their data distributions. By sampling from the clusters, the aggregation process masks the contribution of any single device within the group variance. FCLM not only enhances privacy by breaking the direct lineage between a specific client and the global update but also stabilizes training on heterogeneous data.</p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Security and Robustness</title>
<p>While privacy mechanisms protect data confidentiality, they do not inherently secure the model against integrity attacks. The distributed nature of FL introduces significant attack surfaces, particularly Model Poisoning and Backdoor Attacks, where malicious clients inject deceptive updates to manipulate the global model&#x2019;s behavior [<xref ref-type="bibr" rid="ref-78">78</xref>]. In the context of LLMs, the threats are amplified by the model&#x2019;s vast parameter space and the opacity of deep neural networks. Furthermore, the deployment of federated LLM in wireless and edge environments necessitates robustness against not only malicious actors but also adversarial environmental conditions.</p>
<p>Backdoor attacks in FL typically involve a sophisticated adversary embedding a hidden trigger into the model, causing it to misclassify inputs only when the trigger is present [<xref ref-type="bibr" rid="ref-79">79</xref>]. In the era of LLMs, backdoor attacks have become more complex. The work LBKD [<xref ref-type="bibr" rid="ref-80">80</xref>] highlights a critical vulnerability in specialized domains. Specifically, standard aggregation is insufficient to filter out subtle triggers embedded in domain-specific data. The proposed bidirectional knowledge distillation framework reveals a dual nature: while distillation is often used for model compression, it can also serve as a sophisticated vector for implanting persistent backdoors that survive aggregation. It suggests that the very mechanisms used to make federated LLM efficient require rigorous security auditing to prevent the propagation of malicious traits.</p>
<p>Beyond malicious data injection, the physical transmission medium presents a security challenge. Federated LLM deployments often rely on wireless channels susceptible to noise and intentional jamming. ROFED-LLM [<xref ref-type="bibr" rid="ref-81">81</xref>] addresses the fragility of LLM training in adversarial wireless environments. The study shows that standard robust aggregation algorithms focus primarily on outlier updates caused by data poisoning but fail to account for channel-induced corruption. By modeling the adversarial interference in the wireless spectrum, ROFED-LLM introduces a channel-aware aggregation scheme. It ensures that the global model maintains high fidelity even when the communication links are actively compromised or heavily degraded, a prerequisite for deploying federated LLM in critical infrastructure.</p>
<p>Interestingly, recent research shifts the paradigm from protecting the model to using the model as a protection mechanism, as LLMs possess strong reasoning capabilities that can be harnessed to secure underlying systems.</p>
<p>FedITD [<xref ref-type="bibr" rid="ref-82">82</xref>] exemplifies the idea by applying PEFT to the domain of Insider Threat Detection. Traditional centralized detection systems risk exposing sensitive user logs. FedITD utilizes pre-trained LLMs to analyze behavioral logs locally. By fine-tuning the model via FL, the system learns to identify complex, non-linear patterns of insider threats across an organization without centralizing the raw audit trails. It demonstrates that federated LLM can serve as a potent cybersecurity tool, provided the training process itself remains secure.</p>
<p>Similarly, Luo and Ji [<xref ref-type="bibr" rid="ref-83">83</xref>] propose a framework to enhance the security of Edge-Cloud AI systems. LLMs are employed to monitor data collaboration flows between edge devices and the cloud. The LLM acts as a semantic guardian, identifying anomalous data exchanges that deviate from established security protocols. It creates a symbiotic relationship where the FL framework updates the security model, and the security model, in turn, protects the FL infrastructure.</p>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Alignment and Fairness</title>
<p>Ensuring that LLMs align with human intent and ethical standards is essential. In centralized settings, alignment and fairness are typically achieved through Reinforcement Learning from Human Feedback (RLHF) [<xref ref-type="bibr" rid="ref-20">20</xref>]. However, the federated paradigm introduces unique challenges: human preferences are heterogeneous across clients, and sensitive demographic data required for fairness auditing remains local. Hence, decentralized alignment strategies have been popular to balance global convergence with pluralistic values and rigorous fairness guarantees.</p>
<p>The direct translation of RLHF to federated environments is non-trivial due to the communication overhead of maintaining multiple models (actor, critic, reward, and reference models). FedRLHF [<xref ref-type="bibr" rid="ref-84">84</xref>] addresses the structural impediments by proposing a framework that ensures convergence with privacy preservation. Theoretical guarantees are provided that federated policy optimization can match centralized performance, assuming a coherent global preference exists.</p>
<p>However, the assumption of a single global preference is often flawed. Different cultures and user groups possess distinct values. PluralLLM [<xref ref-type="bibr" rid="ref-85">85</xref>] challenges the one-size-fits-all alignment paradigm. Instead of aggregating conflicting feedback into a diluted global average, the framework facilitates pluralistic alignment. By leveraging the natural data partitioning of FL, PluralLLM allows the model to maintain multiple alignment heads or adapt to diverse value systems, thereby respecting the heterogeneity of the user base rather than suppressing it.</p>
<p>In the literature, Proximal Policy Optimization (PPO) is often considered the standard for RLHF; however, it is computationally intensive on edge devices. Direct Preference Optimization (DPO) [<xref ref-type="bibr" rid="ref-86">86</xref>] has emerged as a resource-efficient alternative. Recent work explores the intersection of DPO and behavioral economics in federated LLMs. KTO [<xref ref-type="bibr" rid="ref-87">87</xref>] investigates how human cognitive biases, specifically loss aversion defined in Prospect Theory, influence federated fine-tuning. The authors argue that standard DPO assumes rational preference labeling. By modeling the non-linear value perception of human annotators (where losses loom larger than gains), the proposed method refines the loss function to better capture true user intent, leading to more robust alignment in distributed settings.</p>
<p>Besides alignment, fairness is also important in LLMs. Fairness in federated LLM is two-fold: ensuring the model does not discriminate based on protected attributes, and ensuring fair representation of client contributions.</p>
<p>In the context of prompt engineering, bias often propagates from the input phrasing. FedPSF-LLM [<xref ref-type="bibr" rid="ref-88">88</xref>] introduces a mechanism to vet prompts locally before the prompts influence the global model. By evaluating the response disparities across demographic groups at the client level, the system filters out prompts that trigger discriminatory outputs, preventing bias from polluting the global aggregation.</p>
<p>Specific domains require even stricter adherence to fairness and privacy. In the Internet of Medical Things, an incorrect or biased recommendation can have life-altering consequences. PFFPO [<xref ref-type="bibr" rid="ref-89">89</xref>] integrates differential privacy with fairness constraints directly into the optimization objective. The method employs a multi-objective approach that maximizes helpfulness while simultaneously minimizing the statistical distance between outputs across different patient demographics. It ensures that the alignment process does not inadvertently favor specific medical profiles over others.</p>
<p>The evaluation of security, privacy, and fairness mechanisms in federated LLMs depends critically on the assumed adversary model. Relevant dimensions include whether the server is honest-but-curious or malicious, whether attackers control one or multiple colluding clients, and whether the attack surface lies in model updates, communication messages, outputs, or retrieval components. Accordingly, reported defense performance should be interpreted together with the attacker&#x2019;s capabilities and prior knowledge.</p>
<p>In practice, the defense mechanisms are commonly evaluated along several complementary dimensions: attack success or backdoor persistence for integrity attacks; exposure risk under membership, reconstruction, or attribute inference for privacy attacks; utility degradation in downstream task performance; and system overhead in communication, latency, or computation. We therefore emphasize that rigorous comparison requires reporting not only defense effectiveness but also the associated privacy-utility-efficiency trade-offs under clearly stated threat assumptions.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Applications</title>
<p>Federated LLMs are increasingly adopted in application domains where data is valuable but difficult to centralize due to privacy, regulation, intellectual property, or operational constraints. In these settings, organizations or devices can collaboratively adapt an LLM to domain-specific language and tasks while keeping raw data local. Compared with conventional deployment of a fixed LLM, federated LLMs offer a path to continuous, distributed improvement from heterogeneous participants, enabling personalization and faster adaptation to shifting terminology, policies, and context. At the same time, real-world applications impose non-trivial requirements beyond model quality, including communication efficiency, on-device resource limits, robustness to non-IID data, compliance with data-governance rules, and protections against leakage and poisoning. The following applications illustrate how the constraints shape practical system designs and highlight recurring evaluation criteria such as utility, latency, privacy risk, and operational reliability.</p>
<p>However, it is important to note that the application literature is uneven in maturity. While some studies report empirical gains on real or institutionally sourced datasets, many others remain proof-of-concept, simulation-based, or prototype-oriented. Therefore, the following discussion distinguishes between demonstrated capabilities under constrained validation settings and aspirational deployment scenarios, particularly in safety-critical domains such as healthcare and finance, where privacy preservation alone is insufficient for real-world adoption.</p>
<sec id="s6_1">
<label>6.1</label>
<title>Healthcare</title>
<p>The biomedical domain is among the most critical yet challenging environments for deploying LLMs. While general-purpose LLMs demonstrate remarkable capabilities in natural language understanding, the direct application in healthcare is impeded by strict privacy regulations, such as GDPR [<xref ref-type="bibr" rid="ref-90">90</xref>], and the siloed nature of medical records. FL has consequently emerged as a vital paradigm, enabling the training of robust biomedical models across distributed institutions without the need for centralized data aggregation. Recent surveys highlight that integrating LLMs into federated healthcare networks offers unique opportunities to address data heterogeneity and scarcity, though significant challenges remain regarding interpretability and communication overhead [<xref ref-type="bibr" rid="ref-91">91</xref>].</p>
<p>One of the most actively explored applications of federated LLMs in healthcare is the extraction of insights from unstructured clinical text, such as physician notes and discharge summaries, although current evidence is still concentrated in prototype studies and controlled evaluations rather than routine clinical deployment. Pharmacovigilance, specifically the identification of Adverse Drug Reactions (ADR), benefits significantly from federated LLMs. By leveraging federated architectures, researchers can aggregate knowledge from diverse patient populations to identify rare side effects without compromising patient anonymity [<xref ref-type="bibr" rid="ref-92">92</xref>]. However, the computational cost of fine-tuning massive language models on local hospital servers, which often lack high-end GPU clusters, acts as a barrier to adoption. To mitigate the resource constraints, recent methodologies propose selective layer fine-tuning. Instead of updating all model parameters or utilizing standard adapters, there are techniques to identify and train only the most relevant layers of the transformer architecture, thereby achieving performance comparable to full fine-tuning while drastically reducing memory usage and communication costs [<xref ref-type="bibr" rid="ref-93">93</xref>].</p>
<p>Beyond static text analysis, modern healthcare requires predictive modeling that accounts for the longitudinal nature of patient history. Electronic Health Records (EHR) are inherently temporal, containing sequences of visits, diagnoses, and treatments. Standard LLMs often treat input data as static context, failing to capture the dynamic progression of chronic conditions. Novel frameworks now incorporate temporal-aware mechanisms within the federated setting. These approaches utilize time-series capable prompts and specialized attention mechanisms to model disease progression, allowing the global model to learn temporal patterns of patient deterioration across multiple hospitals while keeping the raw temporal sequences local [<xref ref-type="bibr" rid="ref-94">94</xref>].</p>
<p>The scope of federated LLM in medicine extends beyond text to multimodal applications, particularly in medical imaging and report generation. In colonoscopy analysis, precise polyp segmentation is critical for early cancer detection. Integrating vision-language foundation models with federated strategies allows for the development of clinically applicable tools. By employing LoRA within a federated framework, institutions can collaboratively refine large vision models for specific segmentation tasks, ensuring high accuracy and privacy preservation simultaneously [<xref ref-type="bibr" rid="ref-95">95</xref>].</p>
<p>More broadly, multimodal federated LLMs deserve explicit attention because many realistic deployments combine text with images, video, waveforms, or sensor streams rather than relying on text alone. A representative case is medical image-report collaboration, where one institution may hold radiology images while another contributes report corpora or downstream annotation expertise. In such settings, federated multimodal adaptation must address not only standard non-IID effects but also cross-modal representation alignment, missing modalities across clients, and stronger privacy risks from perceptual data. Parameter-efficient adaptation can be particularly attractive because it can localize updates to modality-specific encoders or fusion layers, but aggregating such heterogeneous multimodal adapters remains less mature than in text-only federated LLMs. It suggests that multimodal federated LLM applications are promising but remain constrained by limited benchmarks, evaluation protocols, and theory.</p>
<p>Furthermore, the generative capabilities of LLMs have been explored for administrative and diagnostic documentation tasks such as medical report generation and summarization. Existing studies indicate encouraging performance in controlled settings, but broader validation is still needed before these systems can be considered reliable for routine clinical workflows. Generating medical reports from heterogeneous data sources poses a challenge due to the varying data formats and equipment standards across different hospitals. Communication-efficient heterogeneous FL frameworks have been developed to address the issue. The developed systems allow hospitals with different local model architectures or computational capabilities to collaborate on a shared objective, such as generating coherent radiology reports, by exchanging knowledge through prototype alignment or distilled representations rather than raw gradients [<xref ref-type="bibr" rid="ref-96">96</xref>]. It ensures that even smaller clinics with limited infrastructure can benefit from and contribute to state-of-the-art medical report generation systems.</p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Industrial Internet of Things</title>
<p>The integration of LLMs into the Industrial Internet of Things (IIoT) and next-generation networks marks a transition from static sensing to intelligent, semantic reasoning at the edge. A comprehensive review of the synergy suggests that FL is essential for deploying these models in networked systems, primarily to navigate the trade-offs between the computational demands of LLMs and the strict privacy requirements of industrial data [<xref ref-type="bibr" rid="ref-97">97</xref>].</p>
<p>In the realm of autonomous mobility, vehicles act as mobile computing nodes that require real-time decision-making capabilities. Traditional cloud-centric training struggles with the high latency and bandwidth limitations inherent in vehicular networks. To address the issue, recent frameworks like iFLOW have introduced scalable multi-model FL architectures specifically designed for computing on the wheels, enabling cars to collaboratively learn from diverse road conditions without sharing raw sensor streams [<xref ref-type="bibr" rid="ref-98">98</xref>]. Furthermore, the heterogeneity of driving scenarios necessitates robust adaptation techniques. Federated instruction tuning strategies have been proposed to enhance feature diversity, allowing autonomous systems to generalize better across varying traffic environments and rare edge cases [<xref ref-type="bibr" rid="ref-99">99</xref>]. Besides control systems, in-cabin intelligent assistants are also evolving through federated strategies. By applying LoRA to automotive systems, manufacturers can fine-tune LLMs for personalized driver interactions while minimizing the communication overhead associated with transmitting full model updates [<xref ref-type="bibr" rid="ref-100">100</xref>].</p>
<p>Unmanned Aerial Vehicle (UAV) swarms pose distinct challenges, characterized by high mobility and intermittent connectivity. Standard federated protocols often fail when nodes frequently drop out of the network. Specialized algorithms for low-altitude UAV networks now incorporate dropout resilient mechanisms, ensuring that the collaborative fine-tuning of LLMs remains stable even when swarm members disconnect unexpectedly due to interference or battery constraints [<xref ref-type="bibr" rid="ref-101">101</xref>].</p>
<p>Beyond mobility, the manufacturing sector is leveraging federated LLM to enhance the intelligence of digital twins and production lines. Edge-centric architectures are being developed to bring LLM inference closer to the factory floor, addressing the latency requirements of real-time process monitoring [<xref ref-type="bibr" rid="ref-102">102</xref>]. A critical application in manufacturing is the maintenance of Digital Twins, which requires massive amounts of labeled data. Novel asynchronous FL frameworks empower the digital replicas by utilizing LLMs for intelligent data labeling. Such an approach facilitates secure data sharing and model training across different manufacturing sites, effectively bridging the gap between physical assets and the virtual counterparts [<xref ref-type="bibr" rid="ref-103">103</xref>].</p>
<p>The underlying network infrastructure supporting the applications above also benefits from LLMs. As 5G networks become increasingly complex, identifying security threats is critical. FedLLMGuard utilizes federated LLMs to detect anomalies in network traffic, leveraging LLMs&#x2019; semantic understanding to identify subtle attack patterns that traditional rule-based systems might miss [<xref ref-type="bibr" rid="ref-104">104</xref>]. Similarly, in video surveillance, FedVAD enhances anomaly detection by employing GPT-driven semantic distillation. The technique transfers the rich semantic knowledge of large models into lightweight edge detectors, improving the identification of unusual events in video streams while preserving privacy [<xref ref-type="bibr" rid="ref-105">105</xref>].</p>
<p>Finally, the application of federated LLM extends to the design of the hardware itself and scientific discovery. In the complex field of chip design, the FedChip framework demonstrates how federated LLMs can assist in generating and optimizing Verilog code for AI accelerators, allowing disparate design houses to collaborate on better chip architectures without revealing proprietary intellectual property [<xref ref-type="bibr" rid="ref-106">106</xref>]. In scientific modeling, adaptive FL with local LLMs has proven effective for simulating complex photonic and chemical systems, accelerating discovery by aggregating insights from distributed experimental data [<xref ref-type="bibr" rid="ref-107">107</xref>].</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Software Engineering</title>
<p>The application of LLMs to software engineering has revolutionized coding workflows, yet the proprietary nature of commercial source code presents a barrier to centralized training. FL offers a viable path to leverage private code repositories for model improvement without exposing intellectual property. To address the practical constraints of distributed development environments, the F-CodeLLM framework introduces a methodology for adapting LLMs to software tasks across decentralized clients, ensuring that local coding patterns contribute to global model intelligence without raw data leakage [<xref ref-type="bibr" rid="ref-108">108</xref>]. Similarly, adaptive fine-tuning frameworks have been proposed to address the heterogeneity of developer environments, enabling models to dynamically adapt to specific programming languages and project requirements across different organizations [<xref ref-type="bibr" rid="ref-109">109</xref>].</p>
<p>A critical task in software maintenance is understanding legacy code. Recent research explores code summarization techniques that function without direct access to the source text. By leveraging federated strategies, systems can generate natural language descriptions of code functionality while keeping the underlying logic on local servers, thereby maintaining strict confidentiality [<xref ref-type="bibr" rid="ref-110">110</xref>]. Security within the deployment pipeline also benefits from this distributed approach. Novel prompt engineering strategies have been integrated into FL workflows to enhance the detection of malicious code during deployment, ensuring that security checks evolve collaboratively across different nodes to identify emerging threats [<xref ref-type="bibr" rid="ref-111">111</xref>].</p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Text Processing and Generation</title>
<p>Beyond software code, the utility of federated LLMs extends to broader text processing and rule-generation tasks. In the domain of complex event processing (CEP), defining precise rules for event detection is often labor-intensive. Federated LLMs facilitate the automated generation and refinement of CEP rules by aggregating diverse event patterns from multiple sources, thereby improving the system&#x2019;s ability to interpret complex scenarios [<xref ref-type="bibr" rid="ref-112">112</xref>]. Archival science has also seen the introduction of federated intelligence, in which LLMs assist in generating automated descriptions of archival materials. The application allows institutions to modernize their catalogs collaboratively while respecting the privacy or sensitivity of specific historical records [<xref ref-type="bibr" rid="ref-113">113</xref>].</p>
<p>Specialized text and audio processing domains further demonstrate the versatility of federated LLMs. The FL-former architecture adapts the Transformer model for Chinese automatic speech recognition in a federated setting, addressing data scarcity issues often encountered in dialect- or domain-specific datasets [<xref ref-type="bibr" rid="ref-114">114</xref>]. In the entertainment industry, the FedNPC framework utilizes FL to power Non-Player Characters (NPCs) in games. By training on distributed player interactions, game developers can create more dynamic and responsive character dialogues without centralizing massive logs of player behavior [<xref ref-type="bibr" rid="ref-115">115</xref>]. Furthermore, robust aggregation techniques are being applied to multimodal knowledge discovery in computational social systems, allowing researchers to analyze social trends and text data across disparate platforms while mitigating the noise and reliability issues inherent in user-generated content [<xref ref-type="bibr" rid="ref-116">116</xref>]. Besides, FedJudge reports recent advances in federated LLMs for the legal profession [<xref ref-type="bibr" rid="ref-117">117</xref>].</p>
</sec>
<sec id="s6_5">
<label>6.5</label>
<title>Finance</title>
<p>The financial sector operates under some of the most stringent regulatory frameworks regarding data privacy and security, making the centralization of transaction records or customer profiles nearly impossible. Consequently, federated LLMs are increasingly being explored as a way to unlock the value of financial data while remaining more compatible with privacy and compliance constraints [<xref ref-type="bibr" rid="ref-118">118</xref>]. However, much of the current evidence remains at the prototype system and task-specific experimental validation stages. A primary challenge in finance is the computational cost of deploying massive models on the secure, often resource-constrained infrastructure of smaller banks or local branches.</p>
<p>To bridge the gap between model capability and deployment constraints, researchers have introduced Federated Financial Reasoning Distillation [<xref ref-type="bibr" rid="ref-119">119</xref>]. The approach involves a student-teacher paradigm where a compact financial expert model is trained by distilling reasoning capabilities from multiple larger teacher models distributed across different institutions. It allows the smaller model to inherit complex financial reasoning skills, including risk assessment and market trend analysis, without ever directly accessing the teachers&#x2019; private training data. Such strategies democratize access to high-level financial AI, enabling smaller entities to leverage the collective intelligence of the market while maintaining absolute data sovereignty.</p>
<p>Overall, current federated LLM applications in finance are promising for tasks such as risk analysis, reasoning distillation, and panic-index or market-sentiment related analysis, but evidence for deployment in high-stakes decision pipelines remains limited and demands stress testing and regulatory evaluation.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Open Challenges and Future Directions</title>
<p>While the preceding sections show that federated LLMs are technically feasible, a significant gap remains to transition from current experimental prototypes to production-ready deployment. The transition from being workable to being usable requires academia and industry to move beyond simple parameter efficiency and address the systemic tensions inherent in federated LLMs.</p>
<p>This section defines the desired properties of an ideal federated LLM system and then introduces the open challenges and future directions. Specifically, a fully mature federated LLM framework should satisfy the following properties:<list list-type="bullet">
<list-item>
<p>Efficiency (resource-agnostic effectiveness): The system should enable fine-tuning and inference on heterogeneous edge devices without imposing prohibitive memory or bandwidth costs, and without relying on significant cloud-side computational offloading.</p></list-item>
<list-item>
<p>Privacy (verifiable trustworthiness): The system must provide rigorous guarantees that the LLM has not been poisoned, that private data cannot be reconstructed from updates, and that the resulting model aligns with safety guidelines across diverse cultural contexts.</p></list-item>
<list-item>
<p>Utility (synergistic intelligence): The federated LLMs should outperform local isolated training not just in generalization, but in reasoning capabilities, effectively synthesizing fragmented knowledge into a coherent global intelligence without suffering from catastrophic forgetting of the pre-trained base.</p></list-item>
</list></p>
<p>Current methodologies often satisfy one property at the expense of others. As illustrated in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, we term this phenomenon the federated LLM trilemma (balancing efficiency, privacy, and utility). For instance, aggressive quantization (efficiency) may degrade reasoning capabilities (utility), while complex cryptographic defenses (privacy) often introduce latency that makes real-time training on edge devices impossible (efficiency).</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Trilemma of federated LLMs: balancing efficiency, privacy, and utility.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_79321-fig-5.tif"/>
</fig>
<p>In the following, we analyze the critical bottlenecks preventing the realization of the properties above and outline some high-impact research directions to bridge the gaps.</p>
<p><bold>Communication- and computation-efficient federated fine-tuning.</bold> As discussed in <xref ref-type="sec" rid="s4">Section 4</xref>, edge devices are simultaneously the most privacy-sensitive and the most resource-limited participants in federated LLM systems. They often host intimate user data, yet they must operate under stringent constraints on compute, memory, battery, and uplink bandwidth. A critical open problem is therefore to design federated fine-tuning pipelines whose end-to-end cost profiles match the realities of heterogeneous edge fleets, where participation must be robust to intermittent connectivity, stragglers, and highly variable device capabilities. Progress requires moving beyond parameter-efficient as a proxy for being system-level efficient. Even though PEFT reduces the number of trainable parameters, local training can remain bottlenecked by activation memory, optimizer state, and repeated forward and backward passes. Future research should co-design adaptation algorithms and FL protocols to minimize both local computation and communication while preserving convergence under non-IID data. It includes principled approaches to controlling update size and frequency, per-client adaptive training budgets that explicitly incorporate device telemetry, and compression mechanisms that preserve utility when the transmitted signal is already low-dimensional but semantically rich (as in LoRA or prompt vectors). The overarching goal is to make federated fine-tuning a routine, sustainable workload on commodity edge hardware rather than an occasional, high-cost operation reserved for powerful clients. The key research question can be summarized as: how can federated LLM systems jointly minimize communication, memory, and latency without sacrificing adaptation quality?</p>
<p><bold>Federated RAG at scale.</bold> <xref ref-type="sec" rid="s3_4_2">Section 3.4.2</xref> positions federated RAG as a promising strategy for knowledge-intensive tasks when the knowledge base is distributed and cannot be centrally pooled. However, scaling federated RAG introduces a distinctive set of privacy and systems challenges that are not resolved by the assumption that raw documents remain local. In practice, data can be compromised through the retrieval pipeline itself: embeddings, vector indices, retrieval traces, and retrieved contexts can leak sensitive semantics even when underlying documents are never transmitted. As a result, federated RAG requires an explicit threat model and defenses that treat retrieval artifacts as first-class leakage channels. A second open question concerns the secure representation of knowledge. The community lacks a mature understanding of when an embedding space, index structure, or retrieval interface is privacy-preserving against modern inference and reconstruction attacks, particularly when downstream generators can amplify subtle semantic hints. Establishing rigorous notions of leakage for retrieval representations, along with practical mechanisms that mitigate it while retaining retrieval quality, is essential for deployable systems. Finally, federated RAG at real scale must address the fact that global knowledge typically cannot be hosted on any single device. It motivates federated indexing and routing mechanisms that support sharded or hierarchical search across device and infrastructure tiers, enable efficient incremental updates, and enforce access control and auditability across administrative boundaries. The central research challenge is to reconcile retrieval quality, scalability, and privacy guarantees within a single end-to-end design. Key research questions include: how to protect retrieval privacy without significantly harming recall and ranking quality, and what evaluation protocol to use to jointly measure privacy leakage and retrieval effectiveness in federated RAG pipelines.</p>
<p><bold>Privacy mechanisms tailored to LLM adaptation.</bold> <xref ref-type="sec" rid="s5">Section 5</xref> surveys privacy risks and defenses in FL, but federated LLMs increasingly rely on adaptation regimes that diverge from the classical full-gradient assumptions underlying much of the privacy literature. A key future direction is to develop privacy accounting and protection mechanisms that reflect what is actually trained and communicated in federated LLMs, including adapter updates and prompt parameters. Because the objects are smaller but often highly informative, it remains an open empirical and theoretical question whether parameter efficiency improves privacy in practice or merely concentrates sensitive information into a lower-dimensional channel that is easier to analyze and exploit. Split FL further sharpens the problem: intermediate activations can encode substantial information about private inputs, and activation-based leakage may persist even when model updates are protected by secure aggregation. Defenses must therefore be tailored to the representational structure and semantic density of LLM activations, while remaining feasible under the bandwidth and latency constraints of edge deployments. Equally important is the evaluation methodology. Privacy should be treated as a measurable system property rather than an implicit assumption, and leakage testing should be integrated into the standard evaluation loop alongside utility, robustness, and efficiency. In particular, privacy evaluation should explicitly cover inversion and reconstruction risks, membership inference, memorization and regurgitation behaviors, and leakage through retrieval contexts and activations, using standardized protocols that enable meaningful comparisons across methods. Key research questions include: how to evaluate privacy guarantees under realistic federated LLM threat models and whether defenses can provide meaningful protection without unacceptable degradation in utility or system cost.</p>
<p><bold>Standardized federated LLM benchmarks.</bold> A major obstacle to rigorous progress in federated LLM research is the lack of standardized benchmarks and evaluation protocols. Existing studies differ widely in model backbones, parameter scales, hardware constraints, network bandwidth, client participation patterns, privacy mechanisms, and non-IID data distributions, making cross-paper numerical comparisons difficult and sometimes misleading. Future research should therefore develop standardized federated LLM benchmarks with common tasks, shared data partitioning schemes, clearly specified system settings, and unified metrics that cover not only model quality but also communication cost, memory footprint, training time, privacy leakage risk, robustness to attacks, and alignment-related behavior. Such benchmarks would improve reproducibility, enable more meaningful side-by-side comparisons of methods, and help the community distinguish gains owing to algorithmic advances from those caused by differences in experimental setup. In addition, current studies rarely report systematic sensitivity analyses over key hyperparameters that govern the trade-off among efficiency, privacy, and utility, such as LoRA rank, privacy considerations, quantization precision, and client participation ratio. Such an omission makes it difficult to determine the degree of the reported advantages. Future benchmark suites should therefore include controlled ablations and sensitivity sweeps to validate decision frameworks under comparable conditions.</p>
<p><bold>Federated multi-modal foundation models for embodied AI.</bold> Embodied AI is rapidly adopting vision-language and vision-language-action foundation models, and FL is a natural fit because robots and agents collect private, high-dimensional sensor data in homes, workplaces, and other sensitive environments. At the same time, multi-modal adaptation amplifies the central bottlenecks of federated LLMs. Model footprints increase due to vision encoders and fusion modules, activation memory becomes more demanding, and bandwidth constraints become more binding when any intermediate representations must be exchanged. Moreover, heterogeneity is often more severe than in text-only settings: differences in sensors, viewpoints, environments, and tasks induce pronounced distribution shift and continual-learning dynamics. An open problem is thus to develop FL methods that can efficiently and safely adapt multi-modal foundation models under strict memory and bandwidth budgets while keeping raw sensory streams local. It includes principled choices of where and how to apply parameter-efficient adaptation across modality-specific and cross-modal components, and system designs that minimize the exposure of sensitive perceptual information during training and inference. Finally, embodied deployments elevate the importance of robustness and alignment because errors can have physical consequences. Future federated pipelines for embodied AI must therefore integrate safety-critical evaluation and aggregation considerations into the training loop, ensuring that improved average performance does not come at the cost of rare but catastrophic behaviors.</p>
</sec>
<sec id="s8">
<label>8</label>
<title>Conclusion</title>
<p>Federated LLMs represent a promising convergence of foundation-model capability and privacy-preserving collaborative learning. By keeping sensitive data on-device, federated LLMs enable domain adaptation in settings where centralized training is infeasible due to regulatory constraints, confidentiality requirements, or data ownership. At the same time, the scale and complexity of LLMs fundamentally change the design space of federated systems: naive full-parameter federated fine-tuning is often blocked by communication and memory limits, while heterogeneous devices and non-IID data amplify optimization instability. This survey summarizes the rapid progress along three fronts. First, system architectures such as split FL, edge-cloud orchestration, and decentralized protocols extend feasibility across constrained and trust-limited environments. Second, efficient adaptation methods, including federated PEFT, prompt tuning, quantization, zeroth-order optimization, and distillation, substantially reduce resource costs while maintaining strong downstream performance. Third, data security and privacy are becoming first-class concerns, with growing attention to defenses against leakage, robustness against poisoning and backdoors, and federated alignment across heterogeneous human preferences. Despite the advances, federated fine-tuning with higher efficiency, federated RAG at scale, LLM adaptation-specific privacy mechanisms, and federated multi-modal foundation models remain open challenges. Addressing them will be essential for deploying federated LLMs as reliable, compliant, and socially responsible infrastructure across critical domains.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported by the HK RGC Theme-Based Research Scheme (No. T43-513/23-N) and the Pearl River Talent Plan (No. 2024QN11X183).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contributions to the paper as follows: Conceptualization, Shan Jiang and Shichang Xuan; investigation, Wenxin You and Haoran Zhang; writing&#x2014;original draft preparation, Shan Jiang, Wenxin You and Haoran Zhang; writing&#x2014;review and editing, Shan Jiang, Shichang Xuan and Jiaxing Shen; visualization, Wenxin You and Haoran Zhang; supervision, Shan Jiang and Shichang Xuan; funding acquisition, Shan Jiang. All authors reviewed and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Not applicable.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Naveed</surname> <given-names>H</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>AU</given-names></string-name>, <string-name><surname>Qiu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Saqib</surname> <given-names>M</given-names></string-name>, <string-name><surname>Anwar</surname> <given-names>S</given-names></string-name>, <string-name><surname>Usman</surname> <given-names>M</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A comprehensive overview of large language models</article-title>. <source>ACM Trans Intell Syst Technol</source>. <year>2025</year>;<volume>16</volume>(<issue>5</issue>):<fpage>1</fpage>&#x2013;<lpage>72</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3744746</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Achiam</surname> <given-names>J</given-names></string-name>, <string-name><surname>Adler</surname> <given-names>S</given-names></string-name>, <string-name><surname>Agarwal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>L</given-names></string-name>, <string-name><surname>Akkaya</surname> <given-names>I</given-names></string-name>, <string-name><surname>Aleman</surname> <given-names>FL</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Gpt-4 technical report</article-title>. <comment>arXiv:2303.08774. 2023</comment>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Touvron</surname> <given-names>H</given-names></string-name>, <string-name><surname>Lavril</surname> <given-names>T</given-names></string-name>, <string-name><surname>Izacard</surname> <given-names>G</given-names></string-name>, <string-name><surname>Martinet</surname> <given-names>X</given-names></string-name>, <string-name><surname>Lachaux</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Lacroix</surname> <given-names>T</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Llama: open and efficient foundation language models</article-title>. <comment>arXiv:2302.13971. 2023</comment>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chung</surname> <given-names>HW</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Longpre</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zoph</surname> <given-names>B</given-names></string-name>, <string-name><surname>Tay</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Fedus</surname> <given-names>W</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Scaling instruction-finetuned language models</article-title>. <source>J Mach Learn Res</source>. <year>2024</year>;<volume>25</volume>(<issue>70</issue>):<fpage>1</fpage>&#x2013;<lpage>53</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aggarwal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Khullar</surname> <given-names>V</given-names></string-name>, <string-name><surname>Rani</surname> <given-names>S</given-names></string-name>, <string-name><surname>Prola</surname> <given-names>T</given-names></string-name>, <string-name><surname>Bhattacharjee</surname> <given-names>SB</given-names></string-name>, <string-name><surname>Shawon</surname> <given-names>SM</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated learning on internet of things: extensive and systematic review</article-title>. <source>Comput Mater Contin</source>. <year>2024</year>;<volume>79</volume>(<issue>2</issue>):<fpage>1795</fpage>&#x2013;<lpage>834</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2024.049846</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xuan</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Decentralized federated learning based on blockchain: concepts, framework, and challenges</article-title>. <source>Comput Commun</source>. <year>2024</year>;<volume>216</volume>(<issue>1</issue>):<fpage>140</fpage>&#x2013;<lpage>50</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comcom.2023.12.042</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hilmkil</surname> <given-names>A</given-names></string-name>, <string-name><surname>Callh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Barbieri</surname> <given-names>M</given-names></string-name>, <string-name><surname>S&#x00FC;tfeld</surname> <given-names>LR</given-names></string-name>, <string-name><surname>Zec</surname> <given-names>EL</given-names></string-name>, <string-name><surname>Mogren</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Scaling federated learning for fine-tuning of large language models</article-title>. In: <conf-name>International Conference on Applications of Natural Language to Information Systems (NLDB)</conf-name>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2021</year>. p. <fpage>15</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ye</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ge</surname> <given-names>R</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Chai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Yaxin</surname> <given-names>D</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>FedLLM-bench: realistic benchmarks for federated learning of large language models</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2024</year>. p. <fpage>111106</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kuang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Qian</surname> <given-names>B</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>D</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>X</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federatedscope-LLM: a comprehensive package for fine-tuning large language models in federated learning</article-title>. In: <conf-name>Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>5260</fpage>&#x2013;<lpage>71</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ye</surname> <given-names>R</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Chai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>D</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>Y</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>OpenfedLLM: training large language models on decentralized private data via federated learning</article-title>. In: <conf-name>Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>6137</fpage>&#x2013;<lpage>47</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>G</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>From continuous pre-training to alignment: a comprehensive toolkit for large language models in federated learning</article-title>. <source>Neurocomputing</source>. <year>2025</year>;<volume>647</volume>:<fpage>130572</fpage>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cheng</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mao</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Towards federated large language models: motivations, methods, and future directions</article-title>. <source>IEEE Commun Surv Tutor</source>. <year>2025</year>;<volume>27</volume>(<issue>4</issue>):<fpage>2733</fpage>&#x2013;<lpage>64</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>C</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Lyu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>X</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Integration of large language models and federated learning</article-title>. <source>Patterns</source>. <year>2024</year>;<volume>5</volume>(<issue>12</issue>):<fpage>101098</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.patter.2024.101098</pub-id>; <pub-id pub-id-type="pmid">39776850</pub-id></mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Thakur</surname> <given-names>D</given-names></string-name>, <string-name><surname>Guzzo</surname> <given-names>A</given-names></string-name>, <string-name><surname>Fortino</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Analyzing the fusion of federated learning and large language model</article-title>. In: <conf-name>2025 IEEE 5th International Conference on Human-Machine Systems (ICHMS)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>282</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Piccialli</surname> <given-names>F</given-names></string-name>, <string-name><surname>Chiaro</surname> <given-names>D</given-names></string-name>, <string-name><surname>Qi</surname> <given-names>P</given-names></string-name>, <string-name><surname>Bellandi</surname> <given-names>V</given-names></string-name>, <string-name><surname>Damiani</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Federated and edge learning for large language models</article-title>. <source>Inf Fusion</source>. <year>2025</year>;<volume>117</volume>(<issue>1</issue>):<fpage>102840</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.inffus.2024.102840</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ren</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Peng</surname> <given-names>H</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yi</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Advances and open challenges in federated foundation models</article-title>. <source>IEEE Commun Surv Tutor</source>. <year>2025</year>;<volume>28</volume>(<issue>1</issue>):<fpage>2087</fpage>&#x2013;<lpage>126</lpage>. doi:<pub-id pub-id-type="doi">10.1109/comst.2025.3552524</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>D</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated large language model: solutions, challenges and future directions</article-title>. <source>IEEE Wirel Commun</source>. <year>2025</year>;<volume>32</volume>(<issue>4</issue>):<fpage>82</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Vaswani</surname> <given-names>A</given-names></string-name>, <string-name><surname>Shazeer</surname> <given-names>N</given-names></string-name>, <string-name><surname>Parmar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Uszkoreit</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jones</surname> <given-names>L</given-names></string-name>, <string-name><surname>Gomez</surname> <given-names>AN</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>Attention is all you need</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2017</year>. p. <fpage>6000</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Brown</surname> <given-names>T</given-names></string-name>, <string-name><surname>Mann</surname> <given-names>B</given-names></string-name>, <string-name><surname>Ryder</surname> <given-names>N</given-names></string-name>, <string-name><surname>Subbiah</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kaplan</surname> <given-names>JD</given-names></string-name>, <string-name><surname>Dhariwal</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>Language models are few-shot learners</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2020</year>. p. <fpage>1877</fpage>&#x2013;<lpage>901</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ouyang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Almeida</surname> <given-names>D</given-names></string-name>, <string-name><surname>Wainwright</surname> <given-names>C</given-names></string-name>, <string-name><surname>Mishkin</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>Training language models to follow instructions with human feedback</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2022</year>. p. <fpage>27730</fpage>&#x2013;<lpage>44</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Liao</surname> <given-names>G</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Edge large language models: a comprehensive survey</article-title>. <source>CCF Trans Pervasive Comput Interact</source>. <year>2026</year>;<volume>2</volume>(<issue>2</issue>):<fpage>129</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s42486-025-00227-7</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>McMahan</surname> <given-names>B</given-names></string-name>, <string-name><surname>Moore</surname> <given-names>E</given-names></string-name>, <string-name><surname>Ramage</surname> <given-names>D</given-names></string-name>, <string-name><surname>Hampson</surname> <given-names>S</given-names></string-name>, <string-name><surname>Arcas</surname> <given-names>BA</given-names></string-name></person-group>. <article-title>Communication-efficient learning of deep networks from decentralized data</article-title>. In: <conf-name>Proceedings of the 20th International Conference on Artificial Intelligence and Statistics</conf-name>. <publisher-loc>London, UK</publisher-loc>: <publisher-name>PMLR</publisher-name>; <year>2017</year>. p. <fpage>1273</fpage>&#x2013;<lpage>82</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>T</given-names></string-name>, <string-name><surname>Sahu</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Talwalkar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Smith</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Federated learning: challenges, methods, and future directions</article-title>. <source>IEEE Signal Process Mag</source>. <year>2020</year>;<volume>37</volume>(<issue>3</issue>):<fpage>50</fpage>&#x2013;<lpage>60</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Edgeshard: efficient LLM inference via collaborative edge computing</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>;<volume>12</volume>(<issue>10</issue>):<fpage>13119</fpage>&#x2013;<lpage>31</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2024.3524255</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>FedsLLM: federated split learning for large language models over communication networks</article-title>. In: <conf-name>2024 International Conference on Ubiquitous Communication (Ucom)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2024</year>. p. <fpage>438</fpage>&#x2013;<lpage>43</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>L</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ye</surname> <given-names>X</given-names></string-name></person-group>. <article-title>VFLAIR-LLM: a comprehensive framework and benchmark for split learning of LLMs</article-title>. In: <conf-name>Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>5470</fpage>&#x2013;<lpage>81</lpage>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Tan</surname> <given-names>B</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chaddad</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Enhancing large language model fine-tuning with sharpness-aware minimization under split federated learning</article-title>. In: <conf-name>International Conference on Intelligent Computing (ICIC)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>260</fpage>&#x2013;<lpage>71</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yao</surname> <given-names>D</given-names></string-name>, <string-name><surname>Li</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Is split learning privacy-preserving for fine-tuning large language models?</article-title> <source>IEEE Trans Big Data</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.1109/tbdata.2024.3524101</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Djuhera</surname> <given-names>A</given-names></string-name>, <string-name><surname>Andrei</surname> <given-names>VC</given-names></string-name>, <string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>M&#x00F6;nich</surname> <given-names>UJ</given-names></string-name>, <string-name><surname>Boche</surname> <given-names>H</given-names></string-name>, <string-name><surname>Saad</surname> <given-names>W</given-names></string-name></person-group>. <article-title>R-SFLLM: jamming resilient framework for split federated learning with large language models</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2025</year>;<volume>20</volume>:<fpage>8296</fpage>&#x2013;<lpage>311</lpage>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Qiao</surname> <given-names>D</given-names></string-name>, <string-name><surname>Ao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Song</surname> <given-names>F</given-names></string-name>, <string-name><surname>Qin</surname> <given-names>Z</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Tri-AFLLM: resource-efficient adaptive asynchronous accelerated federated LLMs</article-title>. <source>IEEE Trans Circuits Syst Video Technol</source>. <year>2025</year>;<volume>35</volume>(<issue>5</issue>):<fpage>4198</fpage>&#x2013;<lpage>211</lpage>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Iwan</surname> <given-names>I</given-names></string-name>, <string-name><surname>Tanjung</surname> <given-names>SY</given-names></string-name>, <string-name><surname>Yahya</surname> <given-names>BN</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>SL</given-names></string-name></person-group>. <article-title>FedCLLM: federated client selection assisted large language model utilizing domain description</article-title>. <source>Internet Things</source>. <year>2025</year>;<volume>30</volume>:<fpage>101506</fpage>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dun</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Dynamic node scheduling for delay optimization in federated large language model training</article-title>. In: <conf-name>2025 34th International Conference on Computer Communications and Networks (ICCCN)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Huang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Edge-assisted collaborative training method for large language model with embedded data processing unit</article-title>. In: <conf-name>International Conference on Information Processing and Network Provisioning</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>9</fpage>&#x2013;<lpage>19</lpage>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sadeepa</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kavinda</surname> <given-names>K</given-names></string-name>, <string-name><surname>Hashika</surname> <given-names>E</given-names></string-name>, <string-name><surname>Sandeepa</surname> <given-names>C</given-names></string-name>, <string-name><surname>Gamage</surname> <given-names>T</given-names></string-name>, <string-name><surname>Liyanage</surname> <given-names>M</given-names></string-name></person-group>. <article-title>DisLLM: distributed LLMs for privacy assurance in resource-constrained environments</article-title>. In: <conf-name>2024 IEEE Conference on Communications and Network Security (CNS)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2024</year>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>N</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>D</given-names></string-name></person-group>. <article-title>MPCTF: a multi-party collaborative training framework for large language models</article-title>. <source>Electronics</source>. <year>2025</year>;<volume>14</volume>(<issue>16</issue>):<fpage>3253</fpage>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>C</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Xin</surname> <given-names>G</given-names></string-name>, <string-name><surname>Huo</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated transfer learning for on-device LLMs efficient fine tuning optimization</article-title>. <source>Big Data Min Anal</source>. <year>2025</year>;<volume>8</volume>(<issue>2</issue>):<fpage>430</fpage>&#x2013;<lpage>46</lpage>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Jonnalagadda</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Madupati</surname> <given-names>B</given-names></string-name>, <string-name><surname>Vegesna</surname> <given-names>RV</given-names></string-name>, <string-name><surname>Vududala</surname> <given-names>SK</given-names></string-name></person-group>. <article-title>Federated data modeling for LLM deployment in secure cloud-native architectures</article-title>. In: <conf-name>2025 International Conference on Computing Technologies &#x0026; Data Communication (ICCTDC)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Adnan</surname> <given-names>MT</given-names></string-name>, <string-name><surname>Oroceo</surname> <given-names>PA</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>JM</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>DS</given-names></string-name></person-group>. <article-title>PureLLM: a blockchain-driven decentralized PFL for robust and resource-efficient next-gen LLMs</article-title>. In: <conf-name>2025 Sixteenth International Conference on Ubiquitous and Future Networks (ICUFN)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>526</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>R</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Incentive mechanisms for collaborative intelligence sharing in blockchain-based federated LLM fine-tuning</article-title>. In: <conf-name>Blockchain and Web3 Technology Innovation and Application Exchange Conference (BWTAC)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>323</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Nguyen</surname> <given-names>NLB</given-names></string-name>, <string-name><surname>Tran</surname> <given-names>TQ</given-names></string-name>, <string-name><surname>Wong</surname> <given-names>KS</given-names></string-name></person-group>. <article-title>FedDDF: dynamic dataset filtering in federated large language model training</article-title>. In: <conf-name>ASIA CCS&#x2019;25: Proceedings of the International Workshop on Secure and Efficient Federated Learning</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ye</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ge</surname> <given-names>R</given-names></string-name>, <string-name><surname>Yuchi</surname> <given-names>F</given-names></string-name>, <string-name><surname>Chai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>S</given-names></string-name></person-group>. <chapter-title>Leveraging unstructured text data for federated instruction tuning of large language models</chapter-title>. In: <source>International Workshop on Trustworthy Federated Learning</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>119</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Elbakary</surname> <given-names>A</given-names></string-name>, <string-name><surname>Issaid</surname> <given-names>CB</given-names></string-name>, <string-name><surname>ElBatt</surname> <given-names>T</given-names></string-name>, <string-name><surname>Seddik</surname> <given-names>K</given-names></string-name>, <string-name><surname>Bennis</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Mira: a method of federated multi-task learning for large language models</article-title>. <source>IEEE Netw Lett</source>. <year>2025</year>;<volume>7</volume>(<issue>3</issue>):<fpage>171</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>B</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Fedbiot: LLM local fine-tuning in federated learning without full model</article-title>. In: <conf-name>Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>3345</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Xie</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>FedBridgeICL: federated bridging of small and large models for in-context learning</article-title>. In: <conf-name>International Conference on Wireless Artificial Intelligent Computing Systems and Applications (WASA)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Garcia</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gong</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zajac</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hahn</surname> <given-names>A</given-names></string-name></person-group>. <article-title>DF-RAG: a dual federated retrieval-augmented generation framework for collaborative medical AI</article-title>. In: <conf-name>Proceedings of the ACM/IEEE International Conference on Connected Health: Applications, Systems and Engineering Technologies</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>418</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>D</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name></person-group>. <article-title>FwdLLM: efficient federated finetuning of large language models with perturbed inferences</article-title>. In: <conf-name>2024 USENIX Annual Technical Conference</conf-name>. <publisher-loc>Berkeley, CA, USA</publisher-loc>: <publisher-name>USENIX Association</publisher-name>; <year>2024</year>. p. <fpage>579</fpage>&#x2013;<lpage>96</lpage>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Hu</surname> <given-names>EJ</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wallis</surname> <given-names>P</given-names></string-name>, <string-name><surname>Allen-Zhu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>LoRA: low-rank adaptation of large language models</article-title>. <comment>arXiv:2106.09685. 2021</comment>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sun</surname> <given-names>H</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ni</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>J</given-names></string-name>, <string-name><surname>Niyato</surname> <given-names>D</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Federated low-rank adaptation for large models fine-tuning over wireless networks</article-title>. <source>IEEE Trans Wirel Commun</source>. <year>2025</year>;<volume>24</volume>(<issue>1</issue>):<fpage>659</fpage>&#x2013;<lpage>75</lpage>. doi:<pub-id pub-id-type="doi">10.1109/twc.2024.3497998</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Iftikhar</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alsamhi</surname> <given-names>SH</given-names></string-name>, <string-name><surname>Davy</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Enhancing sustainability in LLM training: leveraging federated learning and parameter-efficient fine-tuning</article-title>. <source>IEEE Trans Sustain Comput</source>. <year>2025</year>;<volume>10</volume>(<issue>6</issue>):<fpage>1158</fpage>&#x2013;<lpage>72</lpage>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Low-parameter federated learning with large language models</article-title>. In: <conf-name>International Conference on Web Information Systems and Applications (WISA)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>319</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Bai</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Qian</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name></person-group>. <chapter-title>Federated fine-tuning of large language models under heterogeneous tasks and client resources</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2024</year>. p. <fpage>14457</fpage>&#x2013;<lpage>83</lpage>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Luo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>DynamicFedPEFT: efficient fine-tuning of dynamic federated parameters for large language models</article-title>. In: <conf-name>International Conference on Knowledge Science, Engineering and Management (KSEM)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>89</fpage>&#x2013;<lpage>100</lpage>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Su</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>N</given-names></string-name>, <string-name><surname>Deng</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Federated LLMS fine-tuned with adaptive importance-aware lora</article-title>. In: <conf-name>IEEE International Conference on Communications (ICC)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>6112</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>Z</given-names></string-name>, <string-name><surname>He</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>G</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Lyu</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Flora: federated fine-tuning large language models with heterogeneous low-rank adaptations</article-title>. In: <conf-name>NIPS &#x2019;24: Proceedings of the 38th International Conference on Neural Information Processing Systems</conf-name>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc</publisher-name>.;<year>2024</year>. p. <fpage>22513</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ning</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Qi</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>H</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>D</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated fine-tuning on heterogeneous LoRAs with error-compensated aggregation</article-title>. <source>IEEE Trans Neural Netw Learn Syst</source>. <year>2025</year>;<volume>36</volume>(<issue>10</issue>):<fpage>17826</fpage>&#x2013;<lpage>40</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tnnls.2025.3586545</pub-id>; <pub-id pub-id-type="pmid">40674196</pub-id></mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>An enhanced low-rank fine-tuning framework for federated large language models</article-title>. <source>Neurocomputing</source>. <year>2026</year>;<volume>669</volume>:<fpage>132475</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.neucom.2025.132475</pub-id>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Solat</surname> <given-names>F</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Optimizing client participation in communication-constrained federated LLM adaptation with LoRA</article-title>. <source>Sensors</source>. <year>2025</year>;<volume>25</volume>(<issue>21</issue>):<fpage>6538</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s25216538</pub-id>; <pub-id pub-id-type="pmid">41228760</pub-id></mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yi</surname> <given-names>X</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>B</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>K</given-names></string-name></person-group>. <article-title>FedALoRA: adaptive local LoRA aggregation for personalized federated learning in LLM</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>;<volume>12</volume>(<issue>24</issue>):<fpage>51854</fpage>&#x2013;<lpage>65</lpage>.</mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Che</surname> <given-names>T</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Sheng</surname> <given-names>V</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated learning of large language models with parameter-efficient prompt tuning and adaptive optimization</article-title>. In: <conf-name>Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing</conf-name>. <publisher-loc>Stroudsburg, PA, USA</publisher-loc>: <publisher-name>ACL</publisher-name>; <year>2023</year>. p. <fpage>7871</fpage>&#x2013;<lpage>88</lpage>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gao</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Federated p-tuning based Time-LLM for hotel booking prediction</article-title>. In: <conf-name>Proceedings of the 2025 International Conference on Generative Artificial Intelligence for Business</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>7</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Tanimura</surname> <given-names>T</given-names></string-name>, <string-name><surname>Nakano</surname> <given-names>W</given-names></string-name>, <string-name><surname>Kitagawa</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Takase</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Federated discrete prompt tuning for language models using synthetic examples</article-title>. In: <conf-name>2025 IEEE 22nd Consumer Communications &#x0026; Networking Conference (CCNC)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>4</lpage>.</mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>A</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>B</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated black-box prompt tuning system for large language models on the edge</article-title>. In: <conf-name>Proceedings of the 30th Annual International Conference on Mobile Computing and Networking (MobiCom)</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>1775</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>T</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Federated prompting and chain-of-thought reasoning for improving LLMS answering</article-title>. In: <conf-name>International Conference on Knowledge Science, Engineering and Management (KSEM)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2023</year>. p. <fpage>3</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lv</surname> <given-names>G</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Jia</surname> <given-names>X</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Federated learning and parallel prompt scheduling strategies for large language models</article-title>. In: <conf-name>International Conference on Algorithms and Architectures for Parallel Processing (ICA3PP)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>317</fpage>&#x2013;<lpage>26</lpage>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Qiu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Sheng</surname> <given-names>QZ</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>L</given-names></string-name></person-group>. <article-title>FLM-TopK: expediting federated large language model tuning by sparsifying intervalized gradients</article-title>. In: <conf-name>IEEE INFOCOM 2025&#x2014;IEEE Conference on Computer Communications</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>B</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>FedAdamZO: a zeroth-order adaptive momentum method for memory-efficient fine-tuning of federated large language models</article-title>. In: <conf-name>IEEE International Conference on Multimedia and Expo (ICME)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ling</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>On the convergence of zeroth-order federated tuning for large language models</article-title>. In: <conf-name>Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>1827</fpage>&#x2013;<lpage>38</lpage>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Miao</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Zeroth-order federated private tuning for pretrained large language models</article-title>. In: <conf-name>Australasian Conference on Information Security and Privacy (ACISP)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>285</fpage>&#x2013;<lpage>306</lpage>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gong</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Federated adaptive fine-tuning of large language models with heterogeneous quantization and LoRA</article-title>. In: <conf-name>IEEE Conference on Computer Communications (INFOCOM)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation></ref>
<ref id="ref-70"><label>[70]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>R</given-names></string-name></person-group>. <article-title>FedHO: memory-efficient federated fine-tuning for large models via hybrid gradient computation</article-title>. In: <conf-name>FLEdge-AI &#x2019;25: Proceedings of the Federated Learning and Edge AI for Privacy and Mobility</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>85</fpage>&#x2013;<lpage>92</lpage>.</mixed-citation></ref>
<ref id="ref-71"><label>[71]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>X</given-names></string-name></person-group>. <article-title>FEDNPAIT: federated learning with NADAM and PADAM for instruction tuning</article-title>. In: <conf-name>International Conference on Algorithms and Architectures for Parallel Processing (ICA3PP)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>185</fpage>&#x2013;<lpage>203</lpage>.</mixed-citation></ref>
<ref id="ref-72"><label>[72]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Carlini</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tramer</surname> <given-names>F</given-names></string-name>, <string-name><surname>Wallace</surname> <given-names>E</given-names></string-name>, <string-name><surname>Jagielski</surname> <given-names>M</given-names></string-name>, <string-name><surname>Herbert-Voss</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>K</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Extracting training data from large language models</article-title>. In: <conf-name>30th USENIX Security Symposium (USENIX Security 21)</conf-name>. <publisher-loc>Berkeley, CA, USA</publisher-loc>: <publisher-name>USENIX Association</publisher-name>; <year>2021</year>. p. <fpage>2633</fpage>&#x2013;<lpage>50</lpage>.</mixed-citation></ref>
<ref id="ref-73"><label>[73]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>JY</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Qiu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>HW</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>ZM</given-names></string-name></person-group>. <article-title>Safely learning with private data: a federated learning framework for large language model</article-title>. In: <conf-name>Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing</conf-name>. <publisher-loc>Stroudsburg, PA, USA</publisher-loc>: <publisher-name>ACL</publisher-name>; <year>2024</year>. p. <fpage>5293</fpage>&#x2013;<lpage>306</lpage>.</mixed-citation></ref>
<ref id="ref-74"><label>[74]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>L</given-names></string-name>, <string-name><surname>Fang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>C</given-names></string-name></person-group>. <article-title>An application programming interface (API) sensitive data identification method based on the federated large language model</article-title>. <source>Appl Sci</source>. <year>2024</year>;<volume>14</volume>(<issue>22</issue>):<fpage>10162</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app142210162</pub-id>.</mixed-citation></ref>
<ref id="ref-75"><label>[75]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Data reconstruction and protection in federated learning for fine-tuning large language models</article-title>. <source>IEEE Trans Big Data</source>. <year>2024</year>:<fpage>1&#x2013;13</fpage>. doi:<pub-id pub-id-type="doi">10.1109/TBDATA.2024.3524105</pub-id>.</mixed-citation></ref>
<ref id="ref-76"><label>[76]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Pan</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>J</given-names></string-name></person-group>. <chapter-title>Selective privacy-preserving federated learning for large language model fine-tuning</chapter-title>. In: <source>2025 International Wireless Communications and Mobile Computing (IWCMC)</source>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1626</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-77"><label>[77]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Yun</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bhuiyan</surname> <given-names>ZA</given-names></string-name>, <string-name><surname>Sadi</surname> <given-names>MTAH</given-names></string-name>, <string-name><surname>Su</surname> <given-names>S</given-names></string-name></person-group>. <chapter-title>Privacy-preserving federated learning through clustered sampling on fine-tuning distributed non-iid large language models</chapter-title>. In: <source>2023 IEEE Intl Conf on Parallel &#x0026; Distributed Processing with Applications, Big Data &#x0026; Cloud Computing, Sustainable Computing &#x0026; Communications, Social Computing &#x0026; Networking</source>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2023</year>. p. <fpage>531</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-78"><label>[78]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>S</given-names></string-name></person-group>. <article-title>ELaVFL: efficient verifiable federated learning for large language models</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2025</year>;<volume>22</volume>(<issue>6</issue>):<fpage>6214</fpage>&#x2013;<lpage>29</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2025.3581728</pub-id>.</mixed-citation></ref>
<ref id="ref-79"><label>[79]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bagdasaryan</surname> <given-names>E</given-names></string-name>, <string-name><surname>Veit</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hua</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Estrin</surname> <given-names>D</given-names></string-name>, <string-name><surname>Shmatikov</surname> <given-names>V</given-names></string-name></person-group>. <article-title>How to backdoor federated learning</article-title>. In: <conf-name>Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics</conf-name>. <publisher-loc>London, UK</publisher-loc>: <publisher-name>PMLR</publisher-name>.;<year>2020</year>. p. <fpage>2938</fpage>&#x2013;<lpage>48</lpage>.</mixed-citation></ref>
<ref id="ref-80"><label>[80]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Li</surname> <given-names>B</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>P</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Quek</surname> <given-names>TQS</given-names></string-name></person-group>. <article-title>LBKD: rethinking federated backdoors for low-altitude economy via LLMs and bidirectional knowledge distillation</article-title>. <source>IEEE Trans Netw Sci Eng</source>. <year>2025</year>;<volume>13</volume>(<issue>8</issue>):<fpage>4422</fpage>&#x2013;<lpage>39</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tnse.2025.3626056</pub-id>.</mixed-citation></ref>
<ref id="ref-81"><label>[81]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yin</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>B</given-names></string-name>, <string-name><surname>Zeng</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Rofed-LLM: robust federated learning for large language models in adversarial wireless environments</article-title>. <source>IEEE Trans Netw Sci Eng</source>. <year>2025</year>;<volume>13</volume>:<fpage>1084</fpage>&#x2013;<lpage>96</lpage>.</mixed-citation></ref>
<ref id="ref-82"><label>[82]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>ZQ</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>El Saddik</surname> <given-names>A</given-names></string-name></person-group>. <article-title>FedITD: a federated parameter-efficient tuning with pre-trained large language models and transfer learning framework for insider threat detection</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>160396</fpage>&#x2013;<lpage>417</lpage>.</mixed-citation></ref>
<ref id="ref-83"><label>[83]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Luo</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ji</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Federated learning-based data collaboration method for enhancing edge cloud AI system security using large language models</article-title>. In: <conf-name>2025 5th International Symposium on Computer Technology and Information Science (ISCTIS)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>163</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-84"><label>[84]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Fan</surname> <given-names>FX</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>C</given-names></string-name>, <string-name><surname>Ong</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Wattenhofer</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ooi</surname> <given-names>WT</given-names></string-name></person-group>. <article-title>FedRLHF: a convergence-guaranteed federated framework for privacy-preserving and personalized RLHF</article-title>. In: <conf-name>Proceedings of the 24th International Conference on Autonomous Agents and Multiagent Systems</conf-name>. <publisher-loc>Richland, SC, USA</publisher-loc>: <publisher-name>International Foundation for Autonomous Agents and Multiagent Systems</publisher-name>; <year>2025</year>. p. <fpage>713</fpage>&#x2013;<lpage>21</lpage>.</mixed-citation></ref>
<ref id="ref-85"><label>[85]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Srewa</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>T</given-names></string-name>, <string-name><surname>Elmalaki</surname> <given-names>S</given-names></string-name></person-group>. <article-title>PluralLLM: pluralistic alignment in LLMS via federated learning</article-title>. In: <conf-name>Proceedings of the 3rd International Workshop on Human-Centered Sensing, Modeling, and Intelligent Systems</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>64</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-86"><label>[86]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Rafailov</surname> <given-names>R</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mitchell</surname> <given-names>E</given-names></string-name>, <string-name><surname>Manning</surname> <given-names>CD</given-names></string-name>, <string-name><surname>Ermon</surname> <given-names>S</given-names></string-name>, <string-name><surname>Finn</surname> <given-names>C</given-names></string-name></person-group>. <chapter-title>Direct preference optimization: your language model is secretly a reward model</chapter-title>. In: <source>Advances in neural information processing systems</source>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2023</year>. p. <fpage>53728</fpage>&#x2013;<lpage>41</lpage>.</mixed-citation></ref>
<ref id="ref-87"><label>[87]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Spadea</surname> <given-names>F</given-names></string-name>, <string-name><surname>Seneviratne</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Federated fine-tuning of large language models: Kahneman-Tversky vs. direct preference optimization</article-title>. In: <conf-name>Companion Proceedings of the ACM on Web Conference 2025</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>1757</fpage>&#x2013;<lpage>60</lpage>.</mixed-citation></ref>
<ref id="ref-88"><label>[88]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Song</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Fine-tuning large language models in federated learning with fairness-aware prompt selection</article-title>. <source>Neural Netw</source>. <year>2025</year>;<volume>194</volume>(<issue>8</issue>):<fpage>108160</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.neunet.2025.108160</pub-id>; <pub-id pub-id-type="pmid">41072284</pub-id></mixed-citation></ref>
<ref id="ref-89"><label>[89]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>T</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Privacy and fairness-guaranteed federated preference optimization for large language models in internet of medical things</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2025</year>. doi:<pub-id pub-id-type="doi">10.1109/tce.2025.3595092</pub-id>.</mixed-citation></ref>
<ref id="ref-90"><label>[90]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>L</given-names></string-name>, <string-name><surname>He</surname> <given-names>W</given-names></string-name></person-group>. <article-title>The impact of GDPR on global technology development</article-title>. <source>J Glob Inf Technol Manag</source>. <year>2019</year>;<volume>22</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>6</lpage>. doi:<pub-id pub-id-type="doi">10.1080/1097198x.2019.1569186</pub-id>.</mixed-citation></ref>
<ref id="ref-91"><label>[91]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Peng</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>YP</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Open challenges and opportunities in federated foundation models towards biomedical healthcare</article-title>. <source>BioData Min</source>. <year>2025</year>;<volume>18</volume>(<issue>1</issue>):<fpage>2</fpage>. doi:<pub-id pub-id-type="doi">10.1186/s13040-024-00414-9</pub-id>; <pub-id pub-id-type="pmid">39755653</pub-id></mixed-citation></ref>
<ref id="ref-92"><label>[92]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>D</given-names></string-name>, <string-name><surname>Choo</surname> <given-names>KKR</given-names></string-name></person-group>. <article-title>Applications of federated large language model for adverse drug reactions prediction: scoping review</article-title>. <source>J Med Internet Res</source>. <year>2025</year>;<volume>27</volume>(<issue>12</issue>):<fpage>e68291</fpage>. doi:<pub-id pub-id-type="doi">10.2196/68291</pub-id>; <pub-id pub-id-type="pmid">40921101</pub-id></mixed-citation></ref>
<ref id="ref-93"><label>[93]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Selective layer fine-tuning for federated healthcare NLP: a cost-efficient approach</article-title>. In: <conf-name>2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-94"><label>[94]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Yue</surname> <given-names>F</given-names></string-name>, <string-name><surname>Qiu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Privacy-preserving federated learning framework for disease progression prediction via temporal-aware large language modeling</article-title>. In: <conf-name>2025 International Conference on Sensor-Cloud and Edge Computing System (SCECS)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>414</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-95"><label>[95]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>D</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Anwar</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Shan</surname> <given-names>G</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Towards clinically applicable large-model-based privacy-preserving polyp segmentation: a federated LoRA approach to colonoscopy</article-title>. <source>IEEE J Biomed Health Inform</source>. <year>2025</year>:<fpage>1&#x2013;13</fpage>. doi:<pub-id pub-id-type="doi">10.1109/JBHI.2025.3639279</pub-id>; <pub-id pub-id-type="pmid">41329582</pub-id></mixed-citation></ref>
<ref id="ref-96"><label>[96]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Che</surname> <given-names>H</given-names></string-name>, <string-name><surname>Jin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Jin</surname> <given-names>C</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>H</given-names></string-name></person-group>. <article-title>LLM-driven medical report generation via communication-efficient heterogeneous federated learning</article-title>. <source>IEEE Trans Med Imaging</source>. <year>2026</year>;<volume>45</volume>(<issue>1</issue>):<fpage>28</fpage>&#x2013;<lpage>39</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tmi.2025.3591185</pub-id>; <pub-id pub-id-type="pmid">40690338</pub-id></mixed-citation></ref>
<ref id="ref-97"><label>[97]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yuan</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ni</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>JA</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Synergizing intelligence and privacy: a review of integrating internet of things, large language models, and federated learning in advanced networked systems</article-title>. <source>Appl Sci</source>. <year>2025</year>;<volume>15</volume>(<issue>12</issue>):<fpage>6587</fpage>.</mixed-citation></ref>
<ref id="ref-98"><label>[98]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ammar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>W</given-names></string-name></person-group>. <article-title>iFLOW: an intelligent and scalable multi-model federated learning framework on the wheels</article-title>. <source>IEEE Tran Intell Trans Syst</source>. <year>2025</year>;<volume>26</volume>(<issue>10</issue>):<fpage>15903</fpage>&#x2013;<lpage>14</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tits.2025.3578586</pub-id>.</mixed-citation></ref>
<ref id="ref-99"><label>[99]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>He</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>F</given-names></string-name>, <string-name><surname>Lv</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jia</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Empowering IoT-based autonomous driving via federated instruction tuning with feature diversity</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>;<volume>12</volume>(<issue>6</issue>):<fpage>6095</fpage>&#x2013;<lpage>108</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2024.3518615</pub-id>.</mixed-citation></ref>
<ref id="ref-100"><label>[100]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Messou</surname> <given-names>FJA</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>K</given-names></string-name>, <string-name><surname>Niyato</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Federated fine-tuning of large language models for intelligent automotive systems with low-rank adaptation</article-title>. In: <conf-name>2025 IEEE 101st Vehicular Technology Conference (VTC2025-Spring)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-101"><label>[101]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Nie</surname> <given-names>L</given-names></string-name>, <string-name><surname>Tao</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Enabling privacy-preserving and drop-out resilient federated LLM fine-tuning for the Low-altitude UAV swarm networks</article-title>. <source>IEEE Trans Cogn Commun Netw</source>. <year>2025</year>;<volume>12</volume>:<fpage>2919</fpage>&#x2013;<lpage>36</lpage>.</mixed-citation></ref>
<ref id="ref-102"><label>[102]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Do&#x011F;ruluk</surname> <given-names>E</given-names></string-name>, <string-name><surname>A&#x00E7;&#x0131;kg&#x00F6;z</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Edge-centric federated learning for LLMs in smart manufacturing: architectures, challenges, and opportunities</article-title>. In: <conf-name>2025 4th International Conference on Innovative Mechanisms for Industry Applications (ICIMIA)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>1250</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-103"><label>[103]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sheng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Large language model and digital twins empowered asynchronous federated learning for secure data sharing in intelligent labeling</article-title>. <source>Mathematics</source>. <year>2024</year>;<volume>12</volume>(<issue>22</issue>):<fpage>3550</fpage>. doi:<pub-id pub-id-type="doi">10.3390/math12223550</pub-id>.</mixed-citation></ref>
<ref id="ref-104"><label>[104]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rezaei</surname> <given-names>H</given-names></string-name>, <string-name><surname>Taheri</surname> <given-names>R</given-names></string-name>, <string-name><surname>Shojafar</surname> <given-names>M</given-names></string-name></person-group>. <article-title>FedLLMGuard: a federated large language model for anomaly detection in 5G networks</article-title>. <source>Comput Netw</source>. <year>2025</year>;<volume>269</volume>:<fpage>111473</fpage>.</mixed-citation></ref>
<ref id="ref-105"><label>[105]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Qi</surname> <given-names>F</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Enhancing federated video anomaly detection with GPT-driven semantic distillation</article-title>. In: <conf-name>European Conference on Computer Vision</conf-name>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>234</fpage>&#x2013;<lpage>51</lpage>.</mixed-citation></ref>
<ref id="ref-106"><label>[106]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Nazzal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Nguyen</surname> <given-names>K</given-names></string-name>, <string-name><surname>Vungarala</surname> <given-names>D</given-names></string-name>, <string-name><surname>Zand</surname> <given-names>R</given-names></string-name>, <string-name><surname>Angizi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Phan</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>FedChip: federated LLM for artificial intelligence accelerator chip design</article-title>. In: <conf-name>2025 IEEE International Conference on LLM-Aided Design (ICLAD)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>93</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-107"><label>[107]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khan</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Adaptive federated learning with local large language models for modeling photonic and chemical systems</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>(<issue>3</issue>):<fpage>160559</fpage>&#x2013;<lpage>75</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2025.3606855</pub-id>.</mixed-citation></ref>
<ref id="ref-108"><label>[108]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cai</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Ouyang</surname> <given-names>A</given-names></string-name></person-group>. <article-title>F-codeLLM: a federated learning framework for adapting large language models to practical software development</article-title>. In: <conf-name>Proceedings of the 2024 IEEE/ACM 46th International Conference on Software Engineering: Companion Proceedings</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2024</year>. p. <fpage>416</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-109"><label>[109]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>PS</given-names></string-name></person-group>. <article-title>A federated adaptive large language model fine-tuning framework for software development</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2026</year>;<volume>19</volume>(<issue>1</issue>):<fpage>32</fpage>&#x2013;<lpage>43</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsc.2025.3623626</pub-id>.</mixed-citation></ref>
<ref id="ref-110"><label>[110]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chimalakonda</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Code summarization without direct access to code-towards exploring federated LLMS for software engineering</article-title>. In: <conf-name>Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>100</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-111"><label>[111]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Seo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>N</given-names></string-name>, <string-name><surname>Rong</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Flexible and secure code deployment in federated learning using large language models: prompt engineering to enhance malicious code detection</article-title>. In: <conf-name>2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2023</year>. p. <fpage>341</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-112"><label>[112]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Delouee</surname> <given-names>ML</given-names></string-name>, <string-name><surname>Pernes</surname> <given-names>DG</given-names></string-name>, <string-name><surname>Degeler</surname> <given-names>V</given-names></string-name>, <string-name><surname>Koldehofe</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Towards federated LLM-powered CEP rule generation and refinement</article-title>. In: <conf-name>Proceedings of the 18th ACM International Conference on Distributed and Event-Based Systems</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>185</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-113"><label>[113]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Groppe</surname> <given-names>J</given-names></string-name>, <string-name><surname>Marquet</surname> <given-names>A</given-names></string-name>, <string-name><surname>Walz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Groppe</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Automated archival descriptions with federated intelligence of LLMs</article-title>. In: <conf-name>International Conference on Database and Expert Systems Applications (DEXA)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>53</fpage>&#x2013;<lpage>67</lpage>.</mixed-citation></ref>
<ref id="ref-114"><label>[114]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>FL-former: Chinese automatic speech recognition architecture under the federated large model</article-title>. In: <conf-name>Proceedings of the 2024 3rd International Conference on Artificial Intelligence and Education</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2024</year>. p. <fpage>7</fpage>&#x2013;<lpage>10</lpage>.</mixed-citation></ref>
<ref id="ref-115"><label>[115]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hong</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>S</given-names></string-name>, <string-name><surname>He</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>FedNPC: a federated learning framework for large language models in game NPCs</article-title>. In: <conf-name>2023 IEEE 21st Student Conference on Research and Development (SCOReD)</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2023</year>. p. <fpage>363</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-116"><label>[116]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chakraborty</surname> <given-names>C</given-names></string-name>, <string-name><surname>Polavarapu</surname> <given-names>A</given-names></string-name>, <string-name><surname>Qiu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Alfarraj</surname> <given-names>O</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A robust aggregation of federated large language models for multimodal knowledge discovery in computational social systems</article-title>. <source>IEEE Trans Comput Soc Syst</source>. <year>2025</year>;<volume>12</volume>(<issue>6</issue>):<fpage>5433</fpage>&#x2013;<lpage>48</lpage>.</mixed-citation></ref>
<ref id="ref-117"><label>[117]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Yue</surname> <given-names>L</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Du</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>W</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Fedjudge: federated legal large language model</article-title>. In: <conf-name>International Conference on Database Systems for Advanced Applications (DASFAA)</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>268</fpage>&#x2013;<lpage>85</lpage>.</mixed-citation></ref>
<ref id="ref-118"><label>[118]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>You</surname> <given-names>W</given-names></string-name>, <string-name><surname>Xuan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Decentralized finance security: a survey of attacks, defenses, and open challenges</article-title>. <source>High Confid Comput</source>. <year>2026</year>;<volume>6</volume>(<issue>2</issue>):<fpage>100383</fpage>.</mixed-citation></ref>
<ref id="ref-119"><label>[119]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>L</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>T</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated financial reasoning distillation: training a small financial expert by learning from multiple teachers</article-title>. In: <conf-name>Proceedings of the 6th ACM International Conference on AI in Finance</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>ACM</publisher-name>; <year>2025</year>. p. <fpage>623</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
</ref-list>
</back></article>