Skip to content
Search
paperAugust 2026UnreviewedOpen access

ActivationBackdoor: Backdooring Large Language Models in Collaborative Inference via Intermediate Activations

Zichun Su, Mi Zhang, Xiaohan Zhang, Geng Hong, Xiaoyu You, Min Yang

Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2

Abstract

Collaborative inference enables cost-effective deployment of large language models by partitioning layers across multiple participants and forwarding intermediate activations between participants in a pipeline, but these transmitted activations also create a new attack surface: a malicious participant can manipulate intermediate activations during inference. Prior work on collaborative inference attacks has largely focused on privacy leakage, leaving the backdoor threat insufficiently explored.

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM02Sensitive Information Disclosure
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0024.000Infer Training Data Membership

Suggested from the entry's categories.

Cite

@inproceedings{su2026activationbackdoor,
  title = {{ActivationBackdoor: Backdooring Large Language Models in Collaborative Inference via Intermediate Activations}},
  author = {Zichun Su and Mi Zhang and Xiaohan Zhang and Geng Hong and Xiaoyu You and Min Yang},
  year = {2026},
  month = aug,
  booktitle = {Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2},
  doi = {10.1145/3770855.3818136},
  url = {https://www.semanticscholar.org/paper/2c995168767f95b6d21697890d1d372354864e8e}
}