Skip to content
Search
paperMarch 2026Unreviewed

Backdoor Attacks on Decentralised Post-Training

Oğuzhan Ersoy, Nikolay Blagoev, Jona te Lintelo, Stefanos Koffas, Marina Krček, Stjepan Picek

Abstract

Decentralised post-training of large language models utilises data and pipeline parallelism techniques to split the data and the model. Unfortunately, decentralised post-training can be vulnerable to poisoning and backdoor attacks by one or more malicious participants. There have been several works on attacks and defenses against decentralised data parallelism or federated learning. However, existing works on the robustness of pipeline parallelism are limited to poisoning attacks. To the best of

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{ersoy2026backdoor,
  title = {{Backdoor Attacks on Decentralised Post-Training}},
  author = {Oğuzhan Ersoy and Nikolay Blagoev and Jona te Lintelo and Stefanos Koffas and Marina Krček and Stjepan Picek},
  year = {2026},
  month = mar,
  eprint = {2604.02372},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.02372}
}