Ghost Your System: Audit Fibers Hide Hijacks Behind Passing Checks
Abstract
Deployment pipelines routinely accept non-identical model components produced by quantization, export, or compilation as long as they preserve the behavior checked during qualification. However, qualification observes only the declared component interface, whereas the deployed system later composes that component with downstream consumers. A malicious replacement must preserve every checked output on the same execution it redirects. For reusable components, this requires one fixed replacement that operates across inputs. We show that the check may discard distinctions that downstream consumers still use. The states it treats as equivalent form an audit fiber. We prove that qualification is unsafe whenever a component can reach two states in one fiber that induce different downstream behavior. For normalized representations, we derive an exact targeted attack within the fiber and compile it into FiberRouter, a fixed malicious replacement. Experiments across image and text representations and a Qwen model KV-cache handoff demonstrate reliable downstream hijacking while preserving the qualification that authorizes deployment.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.