כתבה
arXiv cs.AI ·
AGENTQ: תקיפה-מבוקרת-בדיקה של תקיפות-בדיקה על ספריית-LLM
AGENTQ: Quantization-Conditioned Backdoor Attacks on LLM Agents
מחקר חדש מציג תקיפה-מבוקרת-בדיקה של ספריית-LLM, שמאפשרת תקיפה של ספריית-LLM ללא צורך באישון אנושי. התקיפה משתמשת בטכניקה של חיפוש-לורה-פולינומיאלי (PGD) כדי להכניס תקיפה לספריית-LLM, ואז להפעיל אותה כאשר הספריית-LLM נקבעת לגודל-קידוד-מקסימלי (INT8).
תקציר מקורי באנגליתarXiv:2609.14060v1 Announce Type: cross Abstract: Quantization is one of the default deployment paths for open-weight LLM agents, but it is not behavior-preserving: an adversary can release a full-precision checkpoint that passes audits yet misbehaves once quantized, termed as quantization-conditioned attack (QCA). Prior QCA work targets free-text generation, where harm is mediated by a human reader. In contrast, the agentic setting poses a more severe risk: the triggered payload is a structured function that can be executed without human oversight. We present the first study of QCA against LLM agents. We find that directly adapting prior backdoor-injection methods can produce malicious behavior after quantization, but substantially degrades benign utility, rendering the resulting attacks
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית