August 2026Unreviewed
Quantization-Triggered Backdoors in Language Models: Cross-Quantizer Transferability and the Validation--Deployment Gap
Jacopo Dardini, Claudio Stanzione, G. Colò, G. Fenza
Abstract
Post-training quantization is often treated as a semantically neutral optimization for edge deployment of Large Language Models. When a full-precision source checkpoint is evaluated and quantization is applied downstream without equivalent re-evaluation, this workflow creates a structural validation--deployment gap: because quantization is a many-to-one mapping over parameter space, source-precision certification does not guarantee behavioral equivalence in the deployed configuration. We formali
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{dardini2026quantizationtriggered,
title = {{Quantization-Triggered Backdoors in Language Models: Cross-Quantizer Transferability and the Validation--Deployment Gap}},
author = {Jacopo Dardini and Claudio Stanzione and G. Colò and G. Fenza},
year = {2026},
month = aug,
eprint = {2608.27512},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/4814c6bd8be0dc62cbee06a2fb1d391b5cfc7191}
}