LATIDIA · Ciberseguridad
AGENTQ: Ataques de puerta trasera condicionados por cuantificación a agentes de LLM
arXiv: 2609.14060v1Tipo de anuncio: nuevo Resumen: La cuantificación es una de las rutas de implementación predeterminadas para los agentes LLM de peso abierto, pero no preserva el comportamiento: un adversario puede liberar un punto de control de precisión completa que
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.14060v1 Announce Type: new Abstract: Quantization is one of the default deployment paths for open-weight LLM agents, but it is not behavior-preserving: an adversary can release a full-precision checkpoint that passes audits yet misbehaves once quantized, termed as quantization-conditioned attack (QCA). Prior QCA work targets free-text generation, where harm is mediated by a human reader. In contrast, the agentic setting poses a more severe risk: the triggered payload is a structured function that can be executed without human oversight. We present the first study of QCA against LLM agents. We find that directly adapting prior backdoor-injection methods can produce malicious behavior after quantization, but substantially degrades benign utility, rendering the