Pick Your Poison: Learning to Select Poison Sets for Stronger LLM Backdoor Attacks

  • 类型:arxiv
  • 标识:2609.15029
  • 链接:https://arxiv.org/abs/2609.15029
  • 主分类:evaluation
  • 形态:method
  • TLDR:Backdoor poisoning attacks add poisoned examples to otherwise-clean finetuning data, pairing a trigger with a target behavior that the model learns to produce when the trigger appears. Existing evaluations typically fix the number of poisoned examples and sample them at random from a candidate pool. We show that this can severely underestimate worst-case vulnerability: across three LLaMA-3-8B backdoor settings, holding the model, clean data, and poison count fixed, attack success ranges from 3% to 80% depending only on which poison set is chosen. We formalize poison selection as oracle-budgete
  • 待LLM分类:否
  • 来源文件
  • /inbox/tom/_candidates/2026-09-15-agent-rag-longcontext-candidates.json