Skip to content
Search
paperMay 2026Unreviewed

Misrouter: Exploiting Routing Mechanisms for Input-Only Attacks on Mixture-of-Experts LLMs

Zekun Fei, Zihao Wang, Weijie Liu, Ruiqi He, Jianing Geng, Zheli Liu, XiaoFeng Wang

Abstract

Mixture-of-Experts (MoE) architectures have emerged as a leading paradigm for scaling large language models through sparse, routing-based computation. However, this design introduces a new attack surface: the routing mechanism that determines which experts process each input. Prior work shows that manipulating routing can bypass safety alignment, but existing attacks require model modification and thus apply only to locally deployed models. By contrast, real-world LLM services are remotely hoste

Categories

Cite

@misc{fei2026misrouter,
  title = {{Misrouter: Exploiting Routing Mechanisms for Input-Only Attacks on Mixture-of-Experts LLMs}},
  author = {Zekun Fei and Zihao Wang and Weijie Liu and Ruiqi He and Jianing Geng and Zheli Liu and XiaoFeng Wang},
  year = {2026},
  month = may,
  eprint = {2605.04446},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.04446}
}