Skip to content
Search
paperAugust 2026Unreviewed

Quantization-Triggered Backdoors in Language Models: Cross-Quantizer Transferability and the Validation--Deployment Gap

Jacopo Dardini, Claudio Stanzione, G. Colò, G. Fenza

Abstract

Post-training quantization is often treated as a semantically neutral optimization for edge deployment of Large Language Models. When a full-precision source checkpoint is evaluated and quantization is applied downstream without equivalent re-evaluation, this workflow creates a structural validation--deployment gap: because quantization is a many-to-one mapping over parameter space, source-precision certification does not guarantee behavioral equivalence in the deployed configuration. We formali

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{dardini2026quantizationtriggered,
  title = {{Quantization-Triggered Backdoors in Language Models: Cross-Quantizer Transferability and the Validation--Deployment Gap}},
  author = {Jacopo Dardini and Claudio Stanzione and G. Colò and G. Fenza},
  year = {2026},
  month = aug,
  eprint = {2608.27512},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/4814c6bd8be0dc62cbee06a2fb1d391b5cfc7191}
}