<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>adversarial attack detection &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/adversarial-attack-detection/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Tue, 06 Oct 2026 13:57:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>adversarial attack detection &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Mutex-Based Federated Learning Brings Full LLM Fine-Tuning to Edge Devices</title>
		<link>https://scienmag.com/mutex-based-federated-learning-brings-full-llm-fine-tuning-to-edge-devices/</link>
		
		<dc:creator><![CDATA[Veronica Carney]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 13:57:44 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[adversarial attack detection]]></category>
		<category><![CDATA[adversarial attack detection in NLP]]></category>
		<category><![CDATA[distributed systems]]></category>
		<category><![CDATA[edge computing]]></category>
		<category><![CDATA[Edge device federated learning]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[full fine-tuning]]></category>
		<category><![CDATA[full parameter fine-tuning on limited hardware]]></category>
		<category><![CDATA[large language models]]></category>
		<category><![CDATA[large language models for edge AI deployment]]></category>
		<category><![CDATA[LoRa]]></category>
		<category><![CDATA[low-memory neural network training techniques]]></category>
		<category><![CDATA[methodological advancements in federated learning]]></category>
		<category><![CDATA[mutex mechanism]]></category>
		<category><![CDATA[mutex-based large language model fine-tuning]]></category>
		<category><![CDATA[overcoming VRAM limitations in neural network training]]></category>
		<category><![CDATA[privacy-preserving decentralized AI]]></category>
		<category><![CDATA[resource-constrained client training]]></category>
		<category><![CDATA[scalable AI for hospitals and factories]]></category>
		<category><![CDATA[TCAB dataset]]></category>
		<category><![CDATA[TinyLlama]]></category>
		<category><![CDATA[TinyLlama model optimization]]></category>
		<category><![CDATA[TinyLlama-1.1B]]></category>
		<category><![CDATA[VRAM constraints]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=241578</guid>

					<description><![CDATA[Researchers at Marmara University have designed a Mutex-based sequential federated learning architecture that enables full fine-tuning of TinyLlama-1.1B on resource-constrained edge devices, achieving 100 percent training stability and 99.02 percent adversarial attack detection accuracy.]]></description>
										<content:encoded><![CDATA[<p>Large language models have transformed everything from search engines to medical research, but their enormous appetite for memory has left one group of machines largely out in the cold: the modest edge devices scattered across hospitals, factories, phones, and sensor networks. A new study published in Cluster Computing by Sevim Ceylan Bocekci and Kazim Yildiz of Marmara University argues that this exclusion is not a hardware problem at all, but a methodological one. Rather than shrinking the model to fit the machine, the researchers restructured the training process itself, showing that a compact 1.1-billion-parameter language model called TinyLlama can be fully fine-tuned across a federation of resource-constrained clients without a single crash, while simultaneously sharpening its ability to detect adversarial attacks on text classifiers to an accuracy of 99.02 percent.</p>
<p>The core obstacle the team set out to dismantle is well known to anyone who has tried to train modern neural networks on consumer hardware. Full fine-tuning, in which every parameter of a model is updated rather than a frozen subset, demands that the optimizer states, gradients, activations, and model weights all coexist in video random access memory at once. For a billion-parameter model, this translates into many gigabytes of VRAM, far beyond what typical edge hardware offers. Parameter-efficient methods such as LoRA, which freeze the bulk of the network and train only small low-rank adapter matrices, dramatically reduce this footprint, but the authors point to a growing body of evidence that such constrained updates can degrade performance on complex tasks and introduce security vulnerabilities, precisely the wrong trade-off when the task at hand is defending against adversarial manipulation.</p>
<p>Federated learning, the dominant paradigm for training models across distributed devices without centralizing private data, compounds the problem. In the conventional architecture, many clients train simultaneously and send their updates to a coordinating server. When the clients are hosting large language models, the aggregate memory demand of concurrent training routinely exhausts available VRAM and crashes the system. The Marmara researchers observed that this simultaneous-training assumption, inherited from an era of small models, is the true bottleneck. Their solution is conceptually radical in its simplicity: abolish concurrency altogether and let clients take turns.</p>
<p>The distinctive innovation of the proposed architecture is a Mutex-based asynchronous and sequential execution model, borrowing a concept that dates back to Edsger Dijkstra&#8217;s foundational work on concurrent programming control in the 1960s and the later Ricart-Agrawala mutual exclusion algorithm for distributed systems. In the researchers&#8217; design, the GPU is treated as a critical section, a shared resource that only one client may occupy at any given moment. A mutex lock governs access: a client acquires the lock, performs its full fine-tuning round, releases the lock, and only then does the next client begin. This serialization eliminates the peak memory pressure that destroys parallel architectures, because the system never needs to hold more than one training session&#8217;s worth of state in memory at a time.</p>
<p>Serialization alone, however, would be wasteful if the GPU sat idle between rounds or if memory from a completed session lingered and fragmented the available pool. To address this, the architecture applies what the authors describe as aggressive memory deallocation procedures immediately after each training round, flushing tensors, optimizer states, and cached allocations so that the next client starts from a clean slate. The result, demonstrated in experiments on the Text Classification Attack Benchmark, or TCAB, dataset, is a training pipeline that completed the full fine-tuning process with 100 percent stability, while traditional parallel architectures failed outright under the same memory constraints. In distributed systems terms, the researchers traded wall-clock parallelism for guaranteed liveness, a bargain that makes sense when the alternative is not slower training but no training at all.</p>
<p>On the server side, the team confronted a second challenge: how to merge full-parameter updates arriving from clients at unpredictable times without stalling the pipeline. Conventional federated aggregation typically waits for a fixed cohort of clients before averaging their weights, an approach incompatible with a strictly sequential, asynchronous stream of updates. The proposed answer is a technique called Incremental Weight Averaging, which merges each incoming full set of model parameters into the global model as it arrives, keeping latency low and the server never blocked. Because every parameter is updated rather than a low-rank subset, the merged global model retains the complete representational capacity of the underlying language model, avoiding the capability losses the authors associate with parameter-efficient shortcuts.</p>
<p>The application domain that motivated the work is adversarial attack detection, a security problem of growing urgency as language models are deployed in the wild. Adversarial attacks on text classifiers involve subtly perturbing input text, swapping synonyms, inserting characters, or rephrasing sentences, in ways that are nearly invisible to humans but cause the model to misclassify. The TCAB dataset, a large-scale public benchmark of text classification attacks, provides a standardized proving ground for detecting such manipulations. In the researchers&#8217; experiments, the fully fine-tuned TinyLlama model, trained through their sequential federated architecture, reached 99.02 percent accuracy in identifying adversarial inputs, a figure the study attributes to the uncompromised parameter updates that full fine-tuning affords.</p>
<p>The choice of TinyLlama-1.1B as the backbone model is itself a deliberate engineering decision. TinyLlama is an open-source compact language model trained on roughly three trillion tokens, designed to offer competitive language understanding at a scale that can plausibly run on modest hardware. By pairing a deliberately small but capable model with an architecture that never asks the hardware for more than one training session&#8217;s worth of memory, the researchers demonstrate that the frontier of language model training can be pushed down to the edge without resorting to quantization, distillation, or adapter-only tuning, each of which carries documented trade-offs in reasoning quality, robustness, or task performance.</p>
<p>The broader significance of the work lies in its reframing of the hardware-capacity debate. Much of the current literature on federated fine-tuning of large language models focuses on compressing the client-side workload, through low-rank adaptation, quantization, forward-gradient methods, or heterogeneous adapter schemes. The Marmara study takes the opposite stance: preserve the model&#8217;s full capacity and restructure the methodology instead. By treating GPU memory as a mutually exclusive resource and aggregating full-parameter updates incrementally, the architecture converts an intractable concurrency problem into a tractable scheduling one. The authors suggest this opens a path for privacy-preserving, high-capacity language model training in settings where data cannot leave the device and hardware cannot be upgraded, from healthcare networks governed by strict data protection rules to intrusion detection systems in next-generation IoT infrastructures.</p>
<p>Limitations and open questions remain, as with any architectural proposal. Sequential execution means that total training time scales with the number of clients, so very large federations may face scheduling bottlenecks that future work will need to address, perhaps through hierarchical locking or adaptive batching of clients. The study also relies on a single benchmark dataset for its security evaluation, leaving room for validation across other adversarial settings and languages. Nevertheless, the demonstration that full fine-tuning of a billion-parameter language model can run with perfect stability on resource-constrained clients, achieving state-of-the-art adversarial detection accuracy in the process, marks a notable shift in how researchers may approach the tension between model scale and edge hardware. Sometimes, the study suggests, the smartest way to make a model fit the machine is not to make the model smaller, but to make the machines wait their turn.</p>
<p><strong>Subject of Research:</strong> A sequential federated learning architecture for full fine-tuning of large language models on resource-constrained edge devices to detect adversarial attacks</p>
<p><strong>Article Title:</strong> Adversarial attack detection in resource-constrained environments: a stable and sequential federated learning architecture with TinyLlama-1.1B</p>
<p><strong>Article References:</strong> Ceylan Bocekci, S., &amp; Yildiz, K. (2026). Adversarial attack detection in resource-constrained environments: a stable and sequential federated learning architecture with TinyLlama-1.1B. <em>Cluster Computing, 29</em>(14), Article 822. <a href="https://doi.org/10.1007/s10586-026-06630-8" rel="noopener noreferrer">https://doi.org/10.1007/s10586-026-06630-8</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10586-026-06630-8" rel="noopener noreferrer">10.1007/s10586-026-06630-8</a></p>
<p><strong>Keywords:</strong> federated learning, large language models, TinyLlama, full fine-tuning, adversarial attack detection, mutex mechanism, edge computing, LoRA, TCAB dataset, VRAM constraints, distributed systems, TinyLlama-1.1B</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">241578</post-id>	</item>
	</channel>
</rss>
