cs.LGJan 10, 2026

Leveraging Soft Prompts for Privacy Attacks in Federated Prompt Tuning

Authors: Quan Minh Nguyen, Min-Seon Kim, Hoang M. Ngo, Trong Nghia Hoang, Hyuk-Yoon Kwon, My T. Thai

Organizations: CISE, University of Florida, FL, USA · North Carolina State University, NC, USA · Washington State University, WA, USA · Seoul National University of Science and Technology, South Korea

Abstract

Membership inference attacks (MIAs) pose a serious privacy threat in federated learning (FL). While MIAs have been extensively studied in standard FL, the recent shift toward federated fine-tuning introduces new and largely unexplored attack surfaces. In this work, we show that federated prompt-tuning, which adapts pre-trained foundation models using lightweight input prefixes, exposes a novel and effective vector for membership inference. We propose PromptMIA, a membership inference attack tailored to federated prompt-tuning, in which a malicious server introduces adversarially crafted prompts and exploits their updates during collaborative training to determine whether a target data point belongs to a client's private dataset. We formalize this threat via a security game and demonstrate that PromptMIA achieves consistently high attack advantage across diverse benchmark datasets, substantially outperforming current SOTA federated MIAs. We also provide a theoretical lower bound on the attack advantage that explains the observed empirical behavior. Finally, we show that existing MIA defenses are often ineffective against PromptMIA, highlighting the need for defense mechanisms specifically tailored to prompt-tuning in federated settings.

Figures & tables

Appendix figures & tables21 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Toward Efficient Membership Inference Attacks against Federated Large Language Models: A Projection Residual Approach

    Apr 23, 2026Guilin Deng, Silong Chen, Yuchuan Luo +6Membership Inference AttacksFederated Learning

  2. PPFedIT: Towards Privacy-Preserving Federated Instruction Tuning with Few-shot Local Examples

    Mar 10, 2024Zhuo Zhang, Jingyuan Zhang, Jintao Huang +6Federated Learning

  3. Towards Privacy-Preserving Federated Prompt Tuning under Data Heterogeneity: A Subspace-Decomposed Expert Approach

    Jul 23, 2026Yuhua Wang, Xiaodong Li, Yihao Guo +6Soft Prompt TuningHeterogeneity