← Back to search
paper llmsec-2026-00062

MetaBackdoor: Exploiting Positional Encoding as a Backdoor Attack Surface in LLMs

Rui Wen, Mark Russinovich, Andrew Paverd, Jun Sakuma, Ahmed Salem

2026-05

Abstract

Backdoor attacks pose a serious security threat to large language models (LLMs), which are increasingly deployed as general-purpose assistants in safety- and privacy-critical applications. Existing LLM backdoors rely primarily on content-based triggers, requiring explicit modification of the input text. In this work, we show that this assumption is unnecessary and limiting. We introduce MetaBackdoor, a new class of backdoor attacks that exploits positional information as the trigger, without mod

Cite This Resource

@article{llmsec202600062,
  title = {MetaBackdoor: Exploiting Positional Encoding as a Backdoor Attack Surface in LLMs},
  author = {Rui Wen and Mark Russinovich and Andrew Paverd and Jun Sakuma and Ahmed Salem},
  year = {2026},
  url = {https://arxiv.org/abs/2605.15172},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.15172