跳到正文
arXiv:cs.AI· Adam Y. J. Jones, Yu Yuan, Sergio Maffeis·· 3 小时前

针对推测解码的拒绝攻击:Speedbump-P 与 Speedbump-D

Speedbumps: Rejection Attacks on Speculative Decoding

AI 导读

研究者提出推测解码拒绝攻击(SRA),通过在攻击者可控内容后附加对抗后缀,使草稿模型与目标模型更频繁地不一致,从而减少每个草稿周期被接受的 token 数、增加目标模型前向传播次数并拖慢推理。

正文

View PDF HTML (experimental)

Abstract:Speculative decoding is a popular technique for increasing the speed and reducing the costs of large language model (LLM) inference by verifying multiple draft tokens in a single target-model forward pass. The resulting benefit depends on the ability of the drafter to approximate the target model's distribution. In this work, we study Speculative Rejection Attacks (SRAs), a novel class of attacks that cause draft and target models to disagree more often, resulting in fewer draft tokens being accepted per draft cycle. This leads to more target model forward passes needed per generated token, slowing down inference and increasing costs for the victim. We introduce two attacks which append an adversarial suffix to attacker-controlled content to degrade speculative decoding on a victim's prompts. Both attacks optimise the expected length of the accepted speculative prefix, estimating per-depth acceptance from the target's probability of the drafted proposals (Speedbump-P) or from the overlap between the draft and target distributions (Speedbump-D). In some cases, attacks degrade speculative decoding to the point of being slower than autoregressive decoding. The degradation reduces the output quality - regularisation restores output quality but gives up most of the degradation, trading effectiveness for stealthiness. Additionally, the suffixes remain effective under sampling, and transfer across drafters (Speedbump-P) or across target models sharing a drafter (Speedbump-D). These findings identify the draft-target interaction of speculative decoding as a realistic attack surface through which adversarial inputs can inflate inference costs.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.10929 [cs.CR]
  (or arXiv:2610.10929v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.10929

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Adam Jones [view email]
[v1] Wed, 7 Oct 2026 21:35:01 UTC (371 KB)

来源:arXiv:cs.AI · arxiv.org