acceptodds
Under review as a conference paper at ICLR 2027

Ghost Your System: Audit Fibers Hide Hijacks Behind Passing Checks

Abstract

Deployment pipelines routinely accept non-identical model components produced by quantization, export, or compilation as long as they preserve the behavior checked during qualification. However, qualification observes only the declared component interface, whereas the deployed system later composes that component with downstream consumers. A malicious replacement must preserve every checked output on the same execution it redirects. For reusable components, this requires one fixed replacement that operates across inputs. We show that the check may discard distinctions that downstream consumers still use. The states it treats as equivalent form an audit fiber. We prove that qualification is unsafe whenever a component can reach two states in one fiber that induce different downstream behavior. For normalized representations, we derive an exact targeted attack within the fiber and compile it into FiberRouter, a fixed malicious replacement. Experiments across image and text representations and a Qwen model KV-cache handoff demonstrate reliable downstream hijacking while preserving the qualification that authorizes deployment.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.