{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:GFKSQR2BZJVFGAOERX4YSBMWN6","short_pith_number":"pith:GFKSQR2B","schema_version":"1.0","canonical_sha256":"3155284741ca6a5301c48df98905966fb35b47b866e495af7261f1b209906e7b","source":{"kind":"arxiv","id":"2605.15152","version":1},"attestation_state":"computed","paper":{"title":"Widening the Gap: Exploiting LLM Quantization via Outlier Injection","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Kazuki Egashira, Mark Vero, Martin Vechev, Robin Staab, Xiaohua Zhan","submitted_at":"2026-05-14T17:50:39Z","abstract_excerpt":"LLM quantization has become essential for memory-efficient deployment. Recent work has shown that quantization schemes can pose critical security risks: an adversary may release a model that appears benign in full precision but exhibits malicious behavior once quantized by users. However, existing quantization-conditioned attacks have been limited to relatively simple quantization methods, where the attacker can estimate weight regions that remain invariant under the target quantization. Notably, prior attacks have consistently failed to compromise more popular and sophisticated schemes, limit"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.15152","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-14T17:50:39Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"39be25fea9f2124bdd3a366a2f01ae139594914aa56a2ae1db25b3a19943fe70","abstract_canon_sha256":"5ce36563090c053a3b9a4934540a7529ea08a6523f86f5246d44233b2ea93a00"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:38:53.992448Z","signature_b64":"VIt4pHwnXo1r6GaIPKW6ZQ1F21R4QZGGgYVI6x1jwgyTQZA6SydKd7iwvdiahnDXOA+ObAEXYE7IOpArygZJAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3155284741ca6a5301c48df98905966fb35b47b866e495af7261f1b209906e7b","last_reissued_at":"2026-05-17T23:38:53.991646Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:38:53.991646Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Widening the Gap: Exploiting LLM Quantization via Outlier Injection","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Kazuki Egashira, Mark Vero, Martin Vechev, Robin Staab, Xiaohua Zhan","submitted_at":"2026-05-14T17:50:39Z","abstract_excerpt":"LLM quantization has become essential for memory-efficient deployment. Recent work has shown that quantization schemes can pose critical security risks: an adversary may release a model that appears benign in full precision but exhibits malicious behavior once quantized by users. However, existing quantization-conditioned attacks have been limited to relatively simple quantization methods, where the attacker can estimate weight regions that remain invariant under the target quantization. Notably, prior attacks have consistently failed to compromise more popular and sophisticated schemes, limit"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.15152","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.15152","created_at":"2026-05-17T23:38:53.991775+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.15152v1","created_at":"2026-05-17T23:38:53.991775+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.15152","created_at":"2026-05-17T23:38:53.991775+00:00"},{"alias_kind":"pith_short_12","alias_value":"GFKSQR2BZJVF","created_at":"2026-05-18T12:33:37.589309+00:00"},{"alias_kind":"pith_short_16","alias_value":"GFKSQR2BZJVFGAOE","created_at":"2026-05-18T12:33:37.589309+00:00"},{"alias_kind":"pith_short_8","alias_value":"GFKSQR2B","created_at":"2026-05-18T12:33:37.589309+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6","json":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6.json","graph_json":"https://pith.science/api/pith-number/GFKSQR2BZJVFGAOERX4YSBMWN6/graph.json","events_json":"https://pith.science/api/pith-number/GFKSQR2BZJVFGAOERX4YSBMWN6/events.json","paper":"https://pith.science/paper/GFKSQR2B"},"agent_actions":{"view_html":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6","download_json":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6.json","view_paper":"https://pith.science/paper/GFKSQR2B","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.15152&json=true","fetch_graph":"https://pith.science/api/pith-number/GFKSQR2BZJVFGAOERX4YSBMWN6/graph.json","fetch_events":"https://pith.science/api/pith-number/GFKSQR2BZJVFGAOERX4YSBMWN6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6/action/storage_attestation","attest_author":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6/action/author_attestation","sign_citation":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6/action/citation_signature","submit_replication":"https://pith.science/pith/GFKSQR2BZJVFGAOERX4YSBMWN6/action/replication_record"}},"created_at":"2026-05-17T23:38:53.991775+00:00","updated_at":"2026-05-17T23:38:53.991775+00:00"}