SilentStriker:Toward Stealthy Bit-Flip Attacks on Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Xu, Haotian, Peng, Qingsong, Shi, Jie, Zheng, Huadi, Li, Yu, Zhuo, Cheng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915508205387776
author Xu, Haotian
Peng, Qingsong
Shi, Jie
Zheng, Huadi
Li, Yu
Zhuo, Cheng
author_facet Xu, Haotian
Peng, Qingsong
Shi, Jie
Zheng, Huadi
Li, Yu
Zhuo, Cheng
contents The rapid adoption of large language models (LLMs) in critical domains has spurred extensive research into their security issues. While input manipulation attacks (e.g., prompt injection) have been well studied, Bit-Flip Attacks (BFAs) -- which exploit hardware vulnerabilities to corrupt model parameters and cause severe performance degradation -- have received far less attention. Existing BFA methods suffer from key limitations: they fail to balance performance degradation and output naturalness, making them prone to discovery. In this paper, we introduce SilentStriker, the first stealthy bit-flip attack against LLMs that effectively degrades task performance while maintaining output naturalness. Our core contribution lies in addressing the challenge of designing effective loss functions for LLMs with variable output length and the vast output space. Unlike prior approaches that rely on output perplexity for attack loss formulation, which inevitably degrade output naturalness, we reformulate the attack objective by leveraging key output tokens as targets for suppression, enabling effective joint optimization of attack effectiveness and stealthiness. Additionally, we employ an iterative, progressive search strategy to maximize attack efficacy. Experiments show that SilentStriker significantly outperforms existing baselines, achieving successful attacks without compromising the naturalness of generated text.
format Preprint
id arxiv_https___arxiv_org_abs_2509_17371
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SilentStriker:Toward Stealthy Bit-Flip Attacks on Large Language Models
Xu, Haotian
Peng, Qingsong
Shi, Jie
Zheng, Huadi
Li, Yu
Zhuo, Cheng
Cryptography and Security
Machine Learning
The rapid adoption of large language models (LLMs) in critical domains has spurred extensive research into their security issues. While input manipulation attacks (e.g., prompt injection) have been well studied, Bit-Flip Attacks (BFAs) -- which exploit hardware vulnerabilities to corrupt model parameters and cause severe performance degradation -- have received far less attention. Existing BFA methods suffer from key limitations: they fail to balance performance degradation and output naturalness, making them prone to discovery. In this paper, we introduce SilentStriker, the first stealthy bit-flip attack against LLMs that effectively degrades task performance while maintaining output naturalness. Our core contribution lies in addressing the challenge of designing effective loss functions for LLMs with variable output length and the vast output space. Unlike prior approaches that rely on output perplexity for attack loss formulation, which inevitably degrade output naturalness, we reformulate the attack objective by leveraging key output tokens as targets for suppression, enabling effective joint optimization of attack effectiveness and stealthiness. Additionally, we employ an iterative, progressive search strategy to maximize attack efficacy. Experiments show that SilentStriker significantly outperforms existing baselines, achieving successful attacks without compromising the naturalness of generated text.
title SilentStriker:Toward Stealthy Bit-Flip Attacks on Large Language Models
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2509.17371