Skip to content
Search
paperMay 2026Unreviewed

MetaBackdoor: Exploiting Positional Encoding as a Backdoor Attack Surface in LLMs

Rui Wen, Mark Russinovich, Andrew Paverd, Jun Sakuma, Ahmed Salem

Abstract

Backdoor attacks pose a serious security threat to large language models (LLMs), which are increasingly deployed as general-purpose assistants in safety- and privacy-critical applications. Existing LLM backdoors rely primarily on content-based triggers, requiring explicit modification of the input text. In this work, we show that this assumption is unnecessary and limiting. We introduce MetaBackdoor, a new class of backdoor attacks that exploits positional information as the trigger, without mod

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{wen2026metabackdoor,
  title = {{MetaBackdoor: Exploiting Positional Encoding as a Backdoor Attack Surface in LLMs}},
  author = {Rui Wen and Mark Russinovich and Andrew Paverd and Jun Sakuma and Ahmed Salem},
  year = {2026},
  month = may,
  eprint = {2605.15172},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.15172}
}