pith. sign in
Pith Number

pith:6XKPDF4K

pith:2026:6XKPDF4KK2G6KRNHVO332L6I2T
not attested not anchored not stored refs resolved

Mistletoe: Stealthy Acceleration-Collapse Attacks on Speculative Decoding

Bin Chen, Chang Da, Fan Mo, Hao Fang, Kuofeng Gao, Shuoyang Sun, Shu-Tao Xia, Xinhao Zhong, Yi Sun

Mistletoe attacks collapse speculative decoding speedup by slashing average accepted draft length while leaving output quality unchanged.

arxiv:2605.14005 v1 · 2026-05-13 · cs.CL · cs.LG

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{6XKPDF4KK2G6KRNHVO332L6I2T}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

Mistletoe substantially reduces average accepted length τ, collapses speedup, and lowers averaged token throughput, while preserving output quality and perplexity.

C2weakest assumption

The assumption that small perturbations can preserve the target model's visible behavior while substantially reducing draft-token acceptability via null-space projection of degradation gradients.

C3one line summary

Mistletoe is a stealthy attack that collapses the speedup of speculative decoding by reducing average accepted length τ without changing output semantics or perplexity.

References

15 extracted · 15 resolved · 8 Pith anchors

[1] Hydra: Sequentially-dependent draft heads for medusa decoding
[2] Medusa: Simple LLM Inference Acceleration Framework with Multiple Decoding Heads · arXiv:2401.10774
[3] Accelerating Large Language Model Decoding with Speculative Sampling · arXiv:2302.01318
[4] Evaluating Large Language Models Trained on Code · arXiv:2107.03374
[5] Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality.See https://vicuna 2023
Receipt and verification
First computed 2026-05-17T23:39:13.119332Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

f5d4f1978a568de545a7abb7bd2fc8d4c7db6a8f94e6137f4b24625049a5959b

Aliases

arxiv: 2605.14005 · arxiv_version: 2605.14005v1 · doi: 10.48550/arxiv.2605.14005 · pith_short_12: 6XKPDF4KK2G6 · pith_short_16: 6XKPDF4KK2G6KRNH · pith_short_8: 6XKPDF4K
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/6XKPDF4KK2G6KRNHVO332L6I2T \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: f5d4f1978a568de545a7abb7bd2fc8d4c7db6a8f94e6137f4b24625049a5959b
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "e3cc60dc8e75596b52e76d36c94fea39cac98fd01f9c4769032acbd6ce9efc56",
    "cross_cats_sorted": [
      "cs.LG"
    ],
    "license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
    "primary_cat": "cs.CL",
    "submitted_at": "2026-05-13T18:11:42Z",
    "title_canon_sha256": "62e3f32e581681bde61c43d619770be3d8632e779f42938b1439fcf33bd969bd"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2605.14005",
    "kind": "arxiv",
    "version": 1
  }
}