Skip to content
Search
paperMay 2026Unreviewed

Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs

Yifei Wang, Tianlin Li, Xiaohan Zhang, Yida Yang, Xiaoyu Zhang, Li Pan

Abstract

Inference optimization is a vital technique for deploying LLMs at scale. Compilation is the most widely adopted optimization technique for LLMs. While it assumes semantic equivalence between the original and compiled graphs, we first uncover its numerical side effects can be maliciously exploited to implant stealthy backdoors in LLMs. We propose a unified optimization-triggered attack framework comprising two complementary strategies. Without any modification to the compiler or hardware, one str

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{wang2026trusted,
  title = {{Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs}},
  author = {Yifei Wang and Tianlin Li and Xiaohan Zhang and Yida Yang and Xiaoyu Zhang and Li Pan},
  year = {2026},
  month = may,
  eprint = {2605.20641},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.20641}
}