Distributed Subliminal Learning: Replacing Model Updates with Random-Carrier Outputs
Authors: Dario Fenoglio, Gabriele Dominici, Martin Gjoreski, Marc Langheinrich
Organizations: Università della Svizzera italiana (USI), Lugano, Switzerland · MIT Media Lab, Massachusetts Institute of Technology, Cambridge, MA, USA
Collaborative learning typically exchanges model parameters: federated clients communicate updates, while independently adapted foundation models are combined by exchanging adapters or checkpoints. This makes communication scale with model size and requires local specializations to be reconciled in weight space, where interference is common. We ask whether knowledge can instead be shared through model behavior on task-unrelated inputs. We introduce Distributed Subliminal Learning (DSL), a collaborative learning primitive in which participants adapt a common model locally, probe it with task-unrelated inputs, and transmit only the resulting carrier outputs. A coordinator pools these outputs and distills them into a shared model. The primitive supports one-shot foundation-model composition through carrier completions and iterative federated learning through carrier logits, without transmitting model updates or requiring task-related proxy data. In LLM composition, compared with LoRA averaging, DSL achieves higher preference retention (94.56% vs. 87.76%) and a larger GSM8K gain over the base model (22.0 vs. 0.6 points), while reducing upload by 30.6-49.0×. In federated classification, DSL reaches 96.83% on MNIST with 8.9× less uplink than FedAvg and provides lower-communication operating points on CIFAR-10 and Tiny ImageNet. These results establish random-carrier outputs as a practical communication primitive for knowledge sharing across distinct collaborative learning paradigms.
Figures & tables
Figure 1: Distributed Subliminal Learning. Participants adapt a common base model on local data and probe it with task-unrelated random carriers. Instead of model updates or adapters, participants transmit only carrier outputs, illustrated here with random-number completions. The coordinator pools these messages and distills a shared model, combining local specializations in function space. The same principle applies to sampled text completions, probabilities, or logits, and can be used either once for model composition or iteratively in federated learning.
Preference
Local
LoRA Avg.
DSL
Upload (MiB)
Reduction
Cat
98.23
95.60
94.90
2.52
30.6×
Pasta
96.07
85.27
95.00
1.85
41.6×
Maple
98.33
82.40
93.77
1.58
48.8×
Average
97.54
87.76
94.56
–
–
Table 1: Controlled preference composition with Qwen2.5-7B-Instruct. Higher retention is better. DSL upload is measured per participant; reduction is relative to the LoRA payload.
Model
Acc. ( % )
Δ Base (pp)
Upload (MiB)
Reduction
Base model
10.2
–
–
–
Local models (avg.)
58.9
+48.7
–
–
LoRA Avg.
10.8
+0.6
35.27
1.0×
DSL
32.2
+22.0
0.72
49.0×
Table 2: GSM8K composition with Qwen2.5-1.5B-Instruct. Δ reports the accuracy gain over the common base model; upload is measured per participant.
Figure 2: MNIST test accuracy versus total uplink. Increasing the carrier budget moves FSL along an explicit accuracy–communication frontier under the same accounting as the baselines.
MNIST
CIFAR-10
Tiny ImageNet
Method
Acc. (%) ↑
Uplink (GiB) ↓
Acc. (%) ↑
Uplink (GiB) ↓
Acc. (%) ↑
Uplink (GiB) ↓
FedAvg
97.34±0.32
2.37±0.473
66.25±0.67
14.99±1.47
68.12±0.05
0.726±0.048
scaffold
94.62±0.22
8.07±1.12
56.00±2.60
85.72±18.40
65.35±0.73
19.22±2.66
dfrd
97.24±0.27
2.18±0.485
66.46±0.61
11.94±0.283
68.13±0.18
0.685±0.189
FedDF
96.65±0.13
1.61±0.230
66.11±0.60
10.14±1.58
66.92±0.26
0.489±0.169
FedGen
97.26±0.24
2.15±0.408
66.39±1.16
9.32±3.22
61.63±0.52
0.182±0.024
Table 3: Test accuracy and total uplink across datasets, reported as mean ± standard deviation.
Appendix figures & tables8 assets
Supplementary material from the paper’s appendix.
Appendix
Figure 3: Federated Subliminal Learning. In each communication round, clients train locally, probe their models with task-unrelated carriers, and upload only the resulting carrier outputs. The server pools these outputs and distills the next global model, without receiving model updates or task-related proxy data.
M
Protocol
Carrier
Accuracy (%) ↑
Total uplink ↓
4,096
Private
Uniform
41.60±15.42
144.90±112.31 MiB
4,096
Private
Blurred
55.44±0.76
96.60±13.06 MiB
4,096
Private
Fourier
39.38±12.63
120.52±145.48 MiB
4,096
Shared
Uniform
14.58±0.52
27.08±10.22 MiB
4,096
Shared
Blurred
51.17±8.64
193.65±83.49 MiB
4,096
Shared
Fourier
35.87±2.14
31.15±15.38 MiB
Appendix
Table 4: Complete CIFAR-10–ResNet9 carrier sweep. Accuracy and total synthetic uplink are reported as mean ± standard deviation. “Shared-w.” denotes weighted shared-carrier averaging.
M
Protocol
Carrier
Accuracy (%) ↑
Total uplink ↓
2,048
Private
Uniform
96.28±1.21
175.10±58.39 MiB
2,048
Private
Blurred
94.98±0.06
153.02±8.46 MiB
2,048
Private
Fourier
93.78±0.24
109.69±16.63 MiB
2,048
Shared
Uniform
92.70±0.34
192.97±41.23 MiB
2,048
Shared
Blurred
88.34±0.81
77.19±19.59 MiB
2,048
Shared
Fourier
82.94±4.16
52.81±35.42 MiB
Appendix
Table 5: Complete MNIST–MLP carrier sweep. Accuracy and total synthetic uplink are reported as mean ± standard deviation. “Shared-w.” denotes weighted shared-carrier averaging.
M
Protocol
Carrier
Accuracy (%) ↑
Total uplink ↓
1,024
Private
Uniform
75.58±33.80
116.12±104.89 MiB
1,024
Private
Blurred
95.09±0.87
196.35±28.04 MiB
1,024
Private
Fourier
94.98±0.51
179.09±6.12 MiB
1,024
Shared
Uniform
13.95±4.15
3.05±1.02 MiB
1,024
Shared
Blurred
13.25±1.89
3.39 MiB ±600.44 KiB
1,024
Shared
Fourier
36.20±40.92
89.04±148.94 MiB
Appendix
Table 6: Complete MNIST–LeNet5 carrier sweep. Accuracy and total synthetic uplink are reported as mean ± standard deviation. “Shared-w.” denotes weighted shared-carrier averaging.
M
Protocol
Carrier
Accuracy (%) ↑
Total uplink ↓
64
Private
Uniform
60.54±0.58
33.53±2.03 MiB
128
Private
Uniform
61.84±0.35
44.27±17.51 MiB
256
Private
Uniform
62.74±0.32
74.22±14.08 MiB
512
Private
Blurred
60.12±0.19
101.56±0.00 MiB
512
Private
Uniform
63.18±0.32
83.33±16.26 MiB
1,024
Private
Blurred
60.46±0.33
151.04±47.74 MiB
Appendix
Table 7: Private representation-space carrier sweep on Tiny ImageNet using 50k training samples and a frozen ViT-small feature extractor. Accuracy and total synthetic uplink are reported as mean ± standard deviation. The M=1,024 uniform configuration is the Tiny ImageNet FSL setting reported in Table 3 .
M
Uniform (%)
Blurred (%)
512
61.40±0.45
57.45±0.25
1,024
62.04±0.28
58.15±0.10
2,048
61.67±0.36
58.28±0.20
4,096
61.34±0.36
58.69±0.19
Appendix
Table 8: Tiny ImageNet representation-space carrier comparison with a reduced 30k-sample training pool. Results are mean ± standard deviation.
Model
Protocol
M
Carrier
Hquery (%)
Hmarg (%)
ResNet9
Private
4,096
Uniform
31.11±4.79
75.95±1.91
ResNet9
Private
4,096
Blurred
43.31±2.47
84.33±2.20
ResNet9
Private
4,096
Fourier
38.65±0.04
79.68±4.48
ResNet9
Shared-w.
32,768
Uniform
41.42±4.46
53.49±5.32
ResNet9
Shared-w.
32,768
Blurred
49.40±0.99
91.98±1.33
ResNet9
Shared-w.
32,768
Fourier
42.82±4.34
88.05±1.86
Appendix
Table 9: Teacher-output diagnostics on CIFAR-10. Hquery is the normalized mean per-carrier class entropy and Hmarg is the normalized entropy of the mean class distribution. Results are mean ± standard deviation.
Figure 4: Accuracy–communication trade-off as the number of ghost outputs is varied on MNIST. Marker size is proportional to the number of ghosts. Error bars report the standard error.