arXiv AI

Narrow Secret Loyalty Dodges Black-Box Audits

arXiv:2605. 06846v3 Announce Type: replace-cross Abstract: Recent work identifies secret loyalties as a distinct threat from standard backdoors.

arXiv AI
Aug 26

A Formal Methodological Framework for Auditing Robustness and Fidelity in Explainable AI: From Application to Trust Certification

The paper introduces a formal auditing framework to evaluate the robustness and fidelity of post‑hoc explainers such as SHAP and LIME. It defines a Trust Score that combines how stable an explanation is under small input perturbations with how well the highlighted features actually influence the model’s prediction. Experiments on a Madagascar malnutrition dataset show that even highly accurate models can produce unreliable explanations, and that fidelity scores degrade when models overfit.

By Rosa Elysabeth Ralinirina, Jean Christian Ralaivao, Niaiko Micha\"el Ralaivao, Alain Josu\'e Ratovondrahona, Thomas Mahatody
Hugging Face Trending Papers
Jul 29

ToxScreen: Detecting Whether an LLM Has Been Poisoned

As large language models (LLMs) are deployed in high-stakes domains, adversaries may poison training data to implant backdoors: hidden triggers that covertly manipulate model behavior at inference time. We ask whether a defender can recover such a trigger under realistic affordances, namely white-box access to the weights and knowledge of the behavior of concern, but no training data, no trusted reference model, no knowledge of the trigger, and no certainty that the model is poisoned.

arXiv AI
Aug 25

Backdoor Sentinel: Detecting and Detoxifying Backdoors in Diffusion Models via Temporal Noise Consistency

Backdoor Sentinel introduces Temporal Noise Consistency (TNC), a new phenomenon where backdoor activation disrupts noise prediction consistency across adjacent diffusion timesteps, while clean inputs remain stable. Leveraging TNC, the authors propose TNC-Defense, a closed‑loop gray‑box framework that includes TNC‑Detect for auditors to identify and localize anomalous timesteps without accessing model weights, and TNC‑Detox for service providers to perform trigger‑agnostic, timestep‑aware corrections that suppress backdoor behavior. Experiments on five backdoor attacks show an 11% improvement in detection accuracy and a 98.5% invalidation rate of triggered samples with minimal impact on generation quality.

By Bingzheng Wang, Xiaoyan Gu, Hongbo Xu, Hongcheng Li, Zimo Yu, Jiang Zhou, Weiping Wang, Wu Liu
arXiv Machine Learning
Jul 30

ToxScreen: Detecting Whether an LLM Has Been Poisoned

arXiv:2607. 26849v1 Announce Type: cross Abstract: As large language models (LLMs) are deployed in high-stakes domains, adversaries may poison training data to implant backdoors: hidden triggers that covertly manipulate model behavior at inference time.

By Anthony Hughes, Nicole Xing, Collin Francel, Andy Kim, Andrew Draganov
arXiv AI
Aug 28

LoRA as Oracle

The paper introduces a low‑rank auditing method called LoRA as Oracle, which fits a small adapter to a hypothesis and analyzes the geometry, energy, and alignment of the resulting update relative to frozen weights. This approach directly measures what a model has internalized, independent of its output behavior, enabling detection of backdoors that behavioral audits miss. By identifying and erasing malicious internalizations within the same low‑rank subspace, the method consistently detects target classes across multiple datasets and architectures while preserving clean accuracy and operating at far lower parameter and memory cost than full‑model baselines.

By Marco Arazzi, Antonino Nocera