Security/ ai-security · llm-backdoors · inference-optimization · research

Inference Speedups Can Smuggle Hidden Backdoors Into LLMs

New research shows LLM inference speedups can trigger hidden backdoors that evade detection, and the best defenses only cut attack success to 2 percent.

Making a large language model run faster can also make it easier to hijack.

Researchers tested seven open-source LLMs across four tasks and three optimization backends, the techniques like quantization and kernel fusion that companies use to cut inference costs. They first built a narrow, input-specific backdoor, then generalized it into what they call the Universal Optimization Backdoor: a model that behaves normally during standard unoptimized execution but activates its hidden behavior the moment optimization is switched on. In their tests, the universal version hit a 100% attack success rate while leaving the model's everyday accuracy untouched, which means it would sail past backdoor checks that only test unoptimized models. The team also built three defenses, and even the best of those still let the attack succeed as much as 2% of the time.

Most backdoor scanners assume a model behaves identically whether optimized or not. This research shows that assumption doesn't hold, and that the speed tricks nearly every production LLM deployment depends on can double as an attack surface. The gap between the model a security team audited and the model actually serving traffic is exactly where this kind of attack hides.

A 100% success rate in testing and a best-case defense that still lets 1 in 50 attempts through is not a solved problem, it's a new line item on the threat model.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →