{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_ff6ce3e9dc149cd8f8ca1ee1b0239dd878ce970fff8b6fecab32d43c793190d8","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_ff6ce3e9dc149cd8f8ca1ee1b0239dd878ce970fff8b6fecab32d43c793190d8","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"33c286a4e3efaadbf66b573eb38ee349a74e1744966b9f0858bc742599297f6d","published":"Fri, 22 May 2026 00:00:00 -0400","receipt_hash":"33c286a4e3efaadbf66b573eb38ee349a74e1744966b9f0858bc742599297f6d","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"33c286a4e3efaadbf66b573eb38ee349a74e1744966b9f0858bc742599297f6d","observed_at":"2026-05-22T04:43:12.593252Z","parent_run_hash":"dd4d56660d55b2d65dc84dc5e7c8f83487d90da2dd343b5707d6948a3bb0d917","published":"Fri, 22 May 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2605.20641v1 Announce Type: cross \nAbstract: Inference optimization is a vital technique for deploying LLMs at scale. Compilation is the most widely adopted optimization technique for LLMs. While it assumes semantic equivalence between the original and compiled graphs, we first uncover its numerical side effects can be maliciously exploited to implant stealthy backdoors in LLMs. We propose a unified optimization-triggered attack framework comprising two complementary strategies. Without any modification to the compiler or hardware, one strategy flips predictions for specific inputs only when the model is compiled, while the other uses a universal trigger that remains dormant under uncompiled execution but hijacks arbitrary inputs once compilation optimization is applied. Both attacks bypass standard safety evaluations run without compilation. We empirically demonstrate that these optimization-triggered backdoors achieve attack success rates averaging 90% across four mainstream op","title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","url":"https://arxiv.org/abs/2605.20641","vendor":"arxiv_cs_ai"},"summary":"arXiv:2605.20641v1 Announce Type: cross \nAbstract: Inference optimization is a vital technique for deploying LLMs at scale. Compilation is the most widely adopted optimization technique for LLMs. While it assumes semantic equivalence between the original and compiled graphs, we first uncover its numerical side effects can be maliciously exploited to implant stealthy backdoors in LLMs. We propose a unified optimization-triggered attack framework comprising two complementary strategies. Without any modification to the compiler or hardware, one strategy flips predictions for specific inputs only when the model is compiled, while the other uses a universal trigger that remains dormant under uncompiled execution but hijacks arbitrary inputs once compilation optimization is applied. Both attacks bypass standard safety evaluations run without compilation. We empirically demonstrate that these optimization-triggered backdoors achieve attack success rates averaging 90% across four mainstream op","title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-05-22T04:43:12Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2605.20641"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:732f9f717be29f6a7400f6419cbed2603df22d1f7d60ce82a7159e9ec2619e37a39734693a56e00071deb3adf347a3513a20b22a0a862cfb1f529be8a4cf7003","signer":"crovia.substrate","subject":{"observed_at":"2026-05-22T04:43:12Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2605.20641"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"ca01698f757a1aca1308d63cfa755de8546f493d72f460875fad08f42b7ab362","leaf_index":148252,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"bc6be55c6674d895f88c5d0d027ab595d755fbd74e033051d7e38f0df97edadc","side":"right"},{"sibling":"8dc5656d228694e693b968364e70f07944d2bc74760f637f29209f1d4f4e2ea6","side":"right"},{"sibling":"8a369015d1d445251f5f9f924e7af632721e37e167adbcb8fb488e21c2ff76e5","side":"left"},{"sibling":"9312302afc8f18fbc80af335fd5509d01d668cb47f3407e474cf0c856a224646","side":"left"},{"sibling":"b937159ca239abf55d0dfb8f188607b7c440b9f0c419cf53d8bc34e15fb09631","side":"left"},{"sibling":"0cdd6f74518a78e2d51c6d1c6d14d0688bc4da61583f7df49842f7924f36305e","side":"right"},{"sibling":"2f67ce1ca4d405b588b0534baed360bc76fbba6b3678854914e0889a47207afb","side":"right"},{"sibling":"0fa191199f785899b5cc0f48838a3ffb2aa741ddcd9510fe1664869d36a8d31a","side":"right"},{"sibling":"e6aaada16cbe58b790855c6723700fd07821cc6df59048dc470d404b1ba60842","side":"left"},{"sibling":"d337a9fdcfc121e9691d8db9173af6a3fe0c33d4a6d5f0c8a7a01af04f9fb856","side":"left"},{"sibling":"8b39e07457f5cc5d687d2ae42284dbe705bb87084e7db4b626aff81e51dacd19","side":"right"},{"sibling":"79a713e1e345ccb99c5fe994a11708c8e9bcfa2e91f940d70421cb7d8d77ecc6","side":"right"},{"sibling":"249870fb494bef050c409081e5de45f9042938d7b2823524ee496f296aa63667","side":"right"},{"sibling":"96c48ee8328f1b7925a4cc4421df5cb0bd81c92a5d8354c93126fa5f0166d225","side":"right"},{"sibling":"35ca36cee447f0ef7064a25d55f59357c66901e31427729c4c1d8b14aa8adb6c","side":"left"},{"sibling":"4e13b4a3e69bb83d13913477a782913ce03937edd65046853c1964d3cbb6564b","side":"right"},{"sibling":"0f7b2df1c4580bf7bb7c24b9158ba20593a06af18a5f18d0973e5eff20c35cd8","side":"right"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":148601,"merkle_root":"44900cffd986f40535c83f46a250e86fbf1019d41f27080a00fbf9b8d77ec33a","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260524T133701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-05-24T13:37:32Z","sig_algorithm":"ed25519","signature":"059e428c3c5241de303721ad6ac7b748758372180f3f0a717810312aecd6fab073abb3ea264157666de581a2b361c4c6e2aa8ca081b08ce9be090721f0e3400e","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_ff6ce3e9dc149cd8f8ca1ee1b0239dd878ce970fff8b6fecab32d43c793190d8"}}