Mistletoe: Stealthy Acceleration-Collapse Attacks on Speculative Decoding
Abstract
Speculative decoding is widely used to accelerate large language model (LLM) inference by drafting multiple candidate tokens and verifying them with a target model in parallel. Its efficiency critically depends on the average accepted length τ , i.e., how many draft tokens survive each verification step. In this work, we identify a mechanism-level vulnerability in model-based speculative decoding: the drafter approximates the target model distribution, but this approximation is inevitably imperfect. Such a drafter–target mismatch creates an attack surface where small perturbations can preserve the target model’s visible behavior while substantially reducing draft-token acceptability. We propose MISTLETOE, a stealthy accelerationcollapse attack against speculative decoding. It jointly optimizes a degradation objective that decreases drafter–target agreement and a semantic-preservation objective that constrains the target model’s output distribution. To resolve the conflict between these objectives, we introduce a null-space projection mechanism that projects degradation gradients away from the local semantic-preserving direction, suppressing draft acceptance while minimizing semantic drift. Experiments across multiple target models and speculative decoding systems show that MISTLETOE substantially reduces average accepted length τ , collapses speedup, and lowers token throughput, while largely preserving task-level performance. Our work highlights a mechanism-level attack surface in speculative decoding beyond existing output robustness, motivating more robust LLM acceleration systems.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.