acceptodds
Under review as a conference paper at ICLR 2027

Verifiable Robust Federated Inference of LLMs

Abstract

Organisations increasingly favour open-weight large language models (LLMs) because on-premise deployment avoids exposing proprietary assets and private data to third-party APIs. This choice trades one risk for another: open weights can be fine-tuned, quantised, or backdoored by anyone in the supply chain, and a single deployed model becomes a single point of failure whose faults are silent. Federated inference, which queries a diverse ensemble of models and aggregates their outputs, is a natural mitigation, but it only helps if aggregation itself tolerates a subset of faulty or adversarial models. In this work, we study Byzantine-robust federated inference of LLMs, and unlike prior work, we consider proper generation tasks, where the output space is not restricted to single tokens drawn from a small label set for classification tasks. Our key observation is that such tasks supply two resources classification lacks: a partial semantic-equivalence oracle over outputs, and an external verifier induced by executability or formal properties. We combine them in a unified framework based on plurality voting with abstention, which returns an answer only when its support exceeds a consensus threshold , and abstains otherwise. Our theoretical analysis bounds error and abstention for any instantiation of the framework in terms of the Byzantine coincidence rate, honest competence, equivalence oracle completeness, and verifier strength. The consensus threshold then controls the trade-off between error and coverage. We quantify how verifier strength buys plurality margin, and raise fault tolerance from to in ideal conditions. On HumanEval+, our method achieves 0.6% error at 89% coverage, versus 7.3% error for the best base model, and reaches zero error at higher . On MMLU, an adaptive adversary that endorses the largest incorrect cluster reduces accuracy by only 1%.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.