{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:IJ6B5G4OVCLDDZ2MM3BNEH2PKV","short_pith_number":"pith:IJ6B5G4O","schema_version":"1.0","canonical_sha256":"427c1e9b8ea89631e74c66c2d21f4f555f4235e62fadd41d2d1306f93faa4cf2","source":{"kind":"arxiv","id":"2505.23786","version":3},"attestation_state":"computed","paper":{"title":"Mind the Gap: A Practical Attack on GGUF Quantization","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Jingxuan He, Kazuki Egashira, Mark Vero, Martin Vechev, Robin Staab","submitted_at":"2025-05-24T16:30:37Z","abstract_excerpt":"With the increasing size of frontier LLMs, post-training quantization has become the standard for memory-efficient deployment. Recent work has shown that basic rounding-based quantization schemes pose security risks, as they can be exploited to inject malicious behaviors into quantized models that remain hidden in full precision. However, existing attacks cannot be applied to more complex quantization methods, such as the GGUF family used in the popular ollama and llama$.$cpp frameworks. In this work, we address this gap by introducing the first attack on GGUF. Our key insight is that the quan"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.23786","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-05-24T16:30:37Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"f13f8f1348976e71b3739a986aadb850abf766ef989042f5a59b1457583a7303","abstract_canon_sha256":"0d456cdc781d9e9bec230e2183cb04ac5a7ae344787662a5b79bce676e28b3a9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:15:21.586109Z","signature_b64":"JvefoxBLoujmek7xLI2r0P4YzIiuLGEdSeuTONUC9KrEzGEWOB5ADAfPK/T+3NvHBzMeuw+FK8+kodQddNyrCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"427c1e9b8ea89631e74c66c2d21f4f555f4235e62fadd41d2d1306f93faa4cf2","last_reissued_at":"2026-07-05T11:15:21.585623Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:15:21.585623Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Mind the Gap: A Practical Attack on GGUF Quantization","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Jingxuan He, Kazuki Egashira, Mark Vero, Martin Vechev, Robin Staab","submitted_at":"2025-05-24T16:30:37Z","abstract_excerpt":"With the increasing size of frontier LLMs, post-training quantization has become the standard for memory-efficient deployment. Recent work has shown that basic rounding-based quantization schemes pose security risks, as they can be exploited to inject malicious behaviors into quantized models that remain hidden in full precision. However, existing attacks cannot be applied to more complex quantization methods, such as the GGUF family used in the popular ollama and llama$.$cpp frameworks. In this work, we address this gap by introducing the first attack on GGUF. Our key insight is that the quan"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.23786","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.23786/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.23786","created_at":"2026-07-05T11:15:21.585686+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.23786v3","created_at":"2026-07-05T11:15:21.585686+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.23786","created_at":"2026-07-05T11:15:21.585686+00:00"},{"alias_kind":"pith_short_12","alias_value":"IJ6B5G4OVCLD","created_at":"2026-07-05T11:15:21.585686+00:00"},{"alias_kind":"pith_short_16","alias_value":"IJ6B5G4OVCLDDZ2M","created_at":"2026-07-05T11:15:21.585686+00:00"},{"alias_kind":"pith_short_8","alias_value":"IJ6B5G4O","created_at":"2026-07-05T11:15:21.585686+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.29239","citing_title":"Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2605.20641","citing_title":"Trusted Weights, Treacherous Optimizations? Optimization-Triggered Backdoor Attacks on LLMs","ref_index":52,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV","json":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV.json","graph_json":"https://pith.science/api/pith-number/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/graph.json","events_json":"https://pith.science/api/pith-number/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/events.json","paper":"https://pith.science/paper/IJ6B5G4O"},"agent_actions":{"view_html":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV","download_json":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV.json","view_paper":"https://pith.science/paper/IJ6B5G4O","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.23786&json=true","fetch_graph":"https://pith.science/api/pith-number/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/graph.json","fetch_events":"https://pith.science/api/pith-number/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/action/storage_attestation","attest_author":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/action/author_attestation","sign_citation":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/action/citation_signature","submit_replication":"https://pith.science/pith/IJ6B5G4OVCLDDZ2MM3BNEH2PKV/action/replication_record"}},"created_at":"2026-07-05T11:15:21.585686+00:00","updated_at":"2026-07-05T11:15:21.585686+00:00"}