acceptodds
Under review as a conference paper at ICLR 2027

FedPTR: Federated Soft-Prompt Routing under Corrupted Evaluation Feedback

Abstract

Large language models (LLMs) are deployed with libraries of reusable prompts, creating an online routing problem in which each query must be assigned to an appropriate prompt. In collaborative deployments, federated sharing improves routing by pooling cross-client evidence, but also creates a new vulnerability. Manipulated feedback received by honest clients can propagate through protocol-compliant updates and affect clients with clean evaluation channels. We call this cross-client evaluation contamination. This creates a tension between preserving useful sharing and limiting contamination, while standard uncertainty-based influence control cannot distinguish confidence derived locally from that gained through federation. To address this tension, we introduce FedPTR, a corruption-robust framework for federated online soft-prompt routing that controls feedback influence before evaluation scores are revealed. FedPTR contrasts local and federated uncertainty to quantify dependence on cross-client evidence and augments standard uncertainty clipping with federation-aware attenuation. We distinguish manipulated evaluator scores from trusted response utility and establish affected-to-unaffected prediction influence bounds and trusted-utility regret guarantees for both the full federation and unaffected clients. Extensive experiments show that FedPTR limits cross-client contamination while preserving the benefits of federated routing.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.