{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:59:08Z","timestamp":1783702748039,"version":"3.55.0"},"reference-count":47,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T00:00:00Z","timestamp":1761264000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Artif. Intell."],"abstract":"<jats:p>Semantic communication (SemCom) has seen substantial growth in recent years, largely due to its potential to support future intelligent industries. This advancement hinges on the construction and synchronization of robust semantic knowledge bases (SKBs) across multiple endpoints, which can be achieved through large language models (LLMs). However, existing methods for constructing and synchronizing LLM-based SKBs often face numerous security threats, such as privacy leakage and poisoning attacks, particularly when federated fine-tuning is employed to update LLM knowledge bases. To address these challenges, we propose a novel Secure Federated Fine-Tuning (SecFFT) scheme for synchronizing LLM-based SKBs in semantic communication. First, we incorporate homomorphic encryption into SecFFT to ensure the secure synchronization of model parameters. Second, to enhance the trustworthiness of participants against poisoning attacks, we introduce a residual-based access control mechanism, where only participants with low residuals are authenticated to participate in updating the knowledge base. This mechanism is combined with a hash-based message authentication code. Third, we design a self-adaptive local updating strategy to minimize the impact of poisoned model parameters on benign participants, which is crucial for strengthening the robustness of LLM-based knowledge bases against poisoning attacks. Extensive experiments, conducted using four different datasets from the GLUE benchmark, demonstrate that SecFFT can securely synchronize distributed LLM-based SKBs while maintaining high accuracy (98.4% of the performance of the original federated LoRA), with an acceptable additional cost.<\/jats:p>","DOI":"10.3389\/frai.2025.1690950","type":"journal-article","created":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T05:28:44Z","timestamp":1761283724000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Synchronizing LLM-based semantic knowledge bases via secure federated fine-tuning in semantic communication"],"prefix":"10.3389","volume":"8","author":[{"given":"Long","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanhang","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bei","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boyu","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanyuan","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianhua","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2025,10,24]]},"reference":[{"key":"B1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2308.06522","article-title":"Slora: federated parameter efficient fine-tuning of language models","author":"Babakniya","year":"2023","journal-title":"arXiv [preprint]"},{"key":"B2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2402.11505","article-title":"Federated fine-tuning of large language models under heterogeneous language tasks and client resources","author":"Bai","year":"2024","journal-title":"arXiv [preprint]"},{"key":"B3","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1109\/SECON55815.2022.9918536","article-title":"\u201cSkunk\u2014a blockchain and zero trust security enabled federated learning platform for 5g\/6g network slicing,\u201d","volume-title":"2022 19th Annual IEEE International Conference on Sensing, Communication, and Networking (SECON)","author":"Bandara","year":"2022"},{"key":"B4","first-page":"207","author":"Beringer","year":"2015"},{"key":"B5","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2307.08925","article-title":"Federated large language model: a position paper","author":"Chen","year":"2023","journal-title":"arXiv [preprint]"},{"key":"B6","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2202.07962","article-title":"Revisiting parameter-efficient tuning: are we really there yet?","author":"Chen","year":"2022","journal-title":"arXiv [preprint]"},{"key":"B7","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1906.04341","article-title":"What does bert look at? An analysis of bert's attention","author":"Clark","year":"2019","journal-title":"arXiv [preprint]"},{"key":"B8","first-page":"160","article-title":"\u201cAsynchronous multiparty computation: theory and implementation,\u201d","volume-title":"International Workshop on Public Key Cryptography","author":"Damg\u00e5rd","year":"2009"},{"key":"B9","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1007\/s10207-010-0119-9","article-title":"A generalization of paillier's public-key system with applications to electronic voting","volume":"9","author":"Damg\u00e5rd","year":"2010","journal-title":"Int. J. Inf. Secur"},{"key":"B10","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2201.12675","article-title":"Decepticons: Corrupted transformers breach privacy in federated learning for language models","author":"Fowl","year":"2022","journal-title":"arXiv [preprint]"},{"key":"B11","doi-asserted-by":"publisher","first-page":"2328","DOI":"10.1109\/LCOMM.2023.3293805","article-title":"Semantic importance-aware communications using pre-trained language models","volume":"27","author":"Guo","year":"2023","journal-title":"IEEE Commun. Lett"},{"key":"B12","first-page":"2790","article-title":"\u201cParameter-efficient transfer learning for NLP,\u201d","volume-title":"International Conference on Machine Learning","author":"Houlsby","year":"2019"},{"key":"B13","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2106.09685","article-title":"Lora: low-rank adaptation of large language models","author":"Hu","year":"2021","journal-title":"arXiv [preprint]"},{"key":"B14","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2307.03084","article-title":"Opendelta: a plug-and-play library for parameter-efficient adaptation of pre-trained models","author":"Hu","year":"2023","journal-title":"arXiv [preprint]"},{"key":"B15","first-page":"4800","article-title":"\u201cA fast, performant, secure distributed training framework for LLM,\u201d","volume-title":"ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Huang","year":"2024"},{"key":"B16","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2309.01249","article-title":"Large AI model empowered multimodal semantic communications","author":"Jiang","year":"2023","journal-title":"arXiv [preprint]"},{"key":"B17","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1109\/MWC.001.2300346","article-title":"Large AI model-based semantic communications","volume":"31","author":"Jiang","year":"2024","journal-title":"IEEE Wirel. Commun"},{"key":"B18","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MWC.001.2300377","article-title":"Slip: self-supervised learning based model inversion and poisoning detection-based zero-trust systems for vehicular networks","volume":"31","author":"Khowaja","year":"2024","journal-title":"IEEE Wirel. Commun"},{"key":"B19","first-page":"648","article-title":"\u201cOn the security of homomorphic encryption on approximate numbers,\u201d","volume-title":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","author":"Li","year":"2021"},{"key":"B20","doi-asserted-by":"publisher","first-page":"1260","DOI":"10.1109\/TII.2022.3173996","article-title":"Multitentacle federated learning over software-defined industrial internet of things against adaptive poisoning attacks","volume":"19","author":"Li","year":"2022","journal-title":"IEEE Trans. Industr. Inform"},{"key":"B21","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2311.00144","article-title":"Backdoor threats from compromised foundation models to federated learning","author":"Li","year":"2023","journal-title":"arXiv [preprint]"},{"key":"B22","doi-asserted-by":"crossref","first-page":"168","DOI":"10.1007\/978-981-97-2259-4_13","article-title":"\u201cUnveiling backdoor risks brought by foundation models in heterogeneous federated learning,\u201d","volume-title":"Pacific-Asia Conference on Knowledge Discovery and Data Mining","author":"Li","year":"2024"},{"key":"B23","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2101.00190","article-title":"Prefix-tuning: optimizing continuous prompts for generation","author":"Li","year":"2021","journal-title":"arXiv [preprint]"},{"key":"B24","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/TCCN.2024.3435524","article-title":"Generative AI-driven semantic communication networks: architecture, technologies and applications","volume":"11","author":"Liang","year":"2024","journal-title":"IEEE Trans. Cogn. Commun. Netw"},{"key":"B25","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2104.08815","article-title":"Fednlp: benchmarking federated learning methods for natural language processing tasks","author":"Lin","year":"2021","journal-title":"arXiv [preprint]"},{"key":"B26","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1907.11692","article-title":"Roberta: a robustly optimized bert pretraining approach","author":"Liu","year":"2019","journal-title":"arXiv [preprint]"},{"key":"B27","first-page":"1","article-title":"\u201cEfficient knowledge base synchronization in semantic communication network: a federated distillation approach,\u201d","volume-title":"2024 IEEE Wireless Communications and Networking Conference (WCNC)","author":"Lu","year":"2024"},{"key":"B28","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1602.05629","article-title":"Federated learning of deep networks using model averaging","author":"McMahan","year":"2016","journal-title":"arXiv [preprint]"},{"key":"B29","first-page":"223","article-title":"\u201cPublic-key cryptosystems based on composite degree residuosity classes,\u201d","volume-title":"International Conference on the Theory and Applications of Cryptographic Techniques","author":"Paillier","year":"1999"},{"key":"B30","doi-asserted-by":"publisher","first-page":"3580","DOI":"10.1109\/TKDE.2024.3352100","article-title":"Unifying large language models and knowledge graphs: a roadmap","volume":"36","author":"Pan","year":"2024","journal-title":"IEEE Trans. Knowl. Data Eng"},{"key":"B31","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1808.08949","article-title":"Dissecting contextual word embeddings: architecture and representation","author":"Peters","year":"2018","journal-title":"arXiv [preprint]"},{"key":"B32","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/359340.359342","article-title":"A method for obtaining digital signatures and public-key cryptosystems","volume":"21","author":"Rivest","year":"1978","journal-title":"Commun. ACM"},{"key":"B33","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1109\/ICIOT.2018.00019","article-title":"\u201cZero-trust hierarchical management in IOT,\u201d","volume-title":"2018 IEEE International Congress on Internet of Things (ICIOT)","author":"Samaniego","year":"2018"},{"key":"B34","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2010.00309","article-title":"Colake: contextualized language and knowledge embedding","author":"Sun","year":"2020","journal-title":"arXiv [preprint]"},{"key":"B35","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2403.12313","article-title":"Improving lora in privacy-preserving federated learning","author":"Sun","year":"2024","journal-title":"arXiv [preprint]"},{"key":"B36","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1804.07461","article-title":"Glue: a multi-task benchmark and analysis platform for natural language understanding","author":"Wang","year":"2018","journal-title":"arXiv [preprint]"},{"key":"B37","doi-asserted-by":"publisher","first-page":"110677","DOI":"10.1016\/j.asoc.2023.110677","article-title":"Ppflhe: a privacy-preserving federated learning scheme with homomorphic encryption for healthcare data","volume":"146","author":"Wang","year":"2023","journal-title":"Appl. Soft. Comput"},{"key":"B38","doi-asserted-by":"publisher","first-page":"3454","DOI":"10.1109\/TIFS.2020.2988575","article-title":"Federated learning with differential privacy: algorithms and performance analysis","volume":"15","author":"Wei","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur"},{"key":"B39","doi-asserted-by":"crossref","first-page":"85","DOI":"10.1145\/3528580.3532845","article-title":"\u201cHomomorphic encryption and federated learning based privacy-preserving cnn training: COVID-19 detection use-case,\u201d","volume-title":"Proceedings of the 2022 European Interdisciplinary Cybersecurity Conference","author":"Wibawa","year":"2022"},{"key":"B40","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2401.10375","article-title":"Vulnerabilities of foundation model integrated federated learning under adversarial threats","author":"Wu","year":"2024","journal-title":"arXiv [preprint]"},{"key":"B41","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1109\/MNET.2024.3411027","article-title":"Secure semantic communications: fundamentals and challenges","volume":"38","author":"Yang","year":"2024","journal-title":"IEEE Netw"},{"key":"B42","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2106.10199","article-title":"Bitfit: simple parameter-efficient fine-tuning for transformer-based masked language-models","author":"Zaken","year":"2021","journal-title":"arXiv [preprint]"},{"key":"B43","first-page":"493","article-title":"\u201c{BatchCrypt}: efficient homomorphic encryption for {Cross-Silo} federated learning,\u201d","volume-title":"2020 USENIX annual technical conference (USENIX ATC 20)","author":"Zhang","year":"2020"},{"key":"B44","doi-asserted-by":"crossref","first-page":"9963","DOI":"10.18653\/v1\/2023.findings-acl.632","article-title":"\u201cFedpetuning: when federated learning meets the parameter-efficient tuning methods of pre-trained language models,\u201d","volume-title":"Annual Meeting of the Association of Computational Linguistics 2023","author":"Zhang","year":"2023"},{"key":"B45","doi-asserted-by":"publisher","first-page":"832","DOI":"10.1109\/LCOMM.2024.3365158","article-title":"Enhancing reasoning ability in semantic communication through generative ai-assisted knowledge construction","volume":"28","author":"Zhao","year":"2024","journal-title":"IEEE Commun. Lett"},{"key":"B46","doi-asserted-by":"publisher","first-page":"756","DOI":"10.1016\/j.neunet.2023.10.034","article-title":"Learning a robust foundation model against clean-label data poisoning attacks at downstream tasks","volume":"169","author":"Zhou","year":"2024","journal-title":"Neural Netw"},{"key":"B47","article-title":"\u201cDeep leakage from gradients,\u201d","volume-title":"Advance in Neural Information Processing System, 32","author":"Zhu","year":"2019"}],"updated-by":[{"DOI":"10.3389\/frai.2025.1758660","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T00:00:00Z","timestamp":1765843200000}}],"container-title":["Frontiers in Artificial Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/frai.2025.1690950\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T13:15:52Z","timestamp":1765890952000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/frai.2025.1690950\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,24]]},"references-count":47,"alternative-id":["10.3389\/frai.2025.1690950"],"URL":"https:\/\/doi.org\/10.3389\/frai.2025.1690950","relation":{},"ISSN":["2624-8212"],"issn-type":[{"value":"2624-8212","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,24]]},"article-number":"1690950"}}