Researchers have identified a new type of attack, termed Hidden State Poisoning Attack (HiSPA), that specifically targets state space models (SSMs) like Mamba. These attacks induce partial amnesia in the models by overwriting their hidden states, degrading their performance on information retrieval tasks. Experiments show that even advanced hybrid models such as Jamba-1.7-Mini are vulnerable, performing worse on benchmarks like RoBench-25 and Open-Prompt-Injections compared to pure Transformer models. The research also analyzed Mamba-2 and a Mamba-2-based hybrid, Nemotron-3-Nano, and suggests that interpretability studies of Mamba's hidden layers could lead to mitigation strategies. AI
IMPACT Identifies a novel vulnerability in state space models, potentially impacting their security and reliability in real-world applications.
RANK_REASON Academic paper detailing a new type of attack against specific AI models. [lever_c_demoted from research: ic=1 ai=1.0]
- Hidden State Poisoning Attack
- Jamba-1.7-Mini
- Mamba
- Mamba-2
- Nemotron-3-Nano
- Open-Prompt-Injections
- RoBench-25
- State space models
- Transformer
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →