Skip to content
Search
paperSeptember 2026Unreviewed

BadEngram: Backdoor Attack on Gated Memory Components in LLMs

Ariel Fogel, Omer Hofman, Eilon Cohen, Roman Vainshtein

Abstract

To expand open-weight models' capacity without proportionally increasing computation, recent language models incorporate gated parametric memories that retrieve learned values and inject them into intermediate representations. Despite these efficiency benefits, such modules create a distinct attack surface: their parameters can be modified independently of the backbone while directly shaping its computation. We introduce BadEngram, a post-training attack that exploits this surface to implant per

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{fogel2026badengram,
  title = {{BadEngram: Backdoor Attack on Gated Memory Components in LLMs}},
  author = {Ariel Fogel and Omer Hofman and Eilon Cohen and Roman Vainshtein},
  year = {2026},
  month = sep,
  eprint = {2609.13478},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.13478}
}