Now You (Still) See Me: Detecting Evasive Steganographic Payloads in LLMs
arXiv:2606. 09411v1 Announce Type: cross Abstract: Large language models can be fine-tuned to encode prompt-borne secrets into fluent, seemingly benign outputs.
This survey reviews 148 linguistic steganographic methods, 60 countermeasures, 23 evaluation metrics, and 9 open challenges, providing taxonomies, reviews, and adoption analyses. It identifies five paradigm shifts brought by large language models: moving from covertext modification to prompt-only generation, from heuristic to provable security, from white-box symmetric models to black-box or asymmetric access, from security-centric designs to joint optimization, and from text-quality concerns to engineering issues. The paper aims to serve as a reference and roadmap for practical and responsible linguistic steganography in the LLM era.
arXiv:2606. 09411v1 Announce Type: cross Abstract: Large language models can be fine-tuned to encode prompt-borne secrets into fluent, seemingly benign outputs.
arXiv:2604. 20269v2 Announce Type: replace-cross Abstract: With the popularity of the large language models (LLMs), text steganography has achieved remarkable performance.
arXiv:2601. 22818v2 Announce Type: replace-cross Abstract: Fine-tuned LLMs can covertly encode prompt secrets into outputs via steganographic channels.
arXiv:2606. 28425v1 Announce Type: cross Abstract: Increasingly autonomous agentic AI systems pose novel multi-agent risks, such as secret collusion via covert communication channels.
arXiv:2608. 14697v1 Announce Type: new Abstract: Steganography in large language models offers a way to embed hidden messages within natural-sounding text.
arXiv:2511.14301v4 Announce Type: replace-cross Abstract: Transformer-based models are highly susceptible to backdoor attacks via supervised fine-tuning (SFT). To red-team existing data-poisoning def...
The paper introduces CARTS, a steganographic method that uses autoregressive language models to encode a payload text into a stegotext of identical token length by preserving per‑position rank information across contexts. It provides a formal security analysis, proving exact correctness under deterministic model assumptions, and defines key security notions such as context search, key collisions, message equivocation, and non‑commutativity of encoding maps. Empirical tests on Llama 3 8B confirm perfect payload recovery, no random key collisions, and no commuting key pairs, indicating resistance to the studied attack vectors.
arXiv:2602. 14095v2 Announce Type: replace Abstract: Monitoring chain-of-thought (CoT) reasoning is a foundational safety technique for large language model agents; however, this oversight is compromised if models learn to conceal their reasoning.
arXiv:2606. 09135v1 Announce Type: cross Abstract: We demonstrate that widely deployed Large Language Model (LLM) inference stacks harbor a steganographic channel that requires no modification to model weights, sampling code, or output distributions.
arXiv:2512. 13325v2 Announce Type: replace-cross Abstract: Securing digital text is becoming increasingly relevant due to the widespread use of large language models.
arXiv:2605. 26595v2 Announce Type: replace-cross Abstract: Large language models (LLMs) are often fine-tuned on uncurated text datasets that adversaries can poison.
arXiv:2503.04332v2 Announce Type: replace-cross Abstract: The tremendous commercial potential of large language models (LLMs) has heightened concerns over their unauthorized use. To address this, we...