English

STAR: Detecting Inference-time Backdoors in LLM Reasoning via State-Transition Amplification Ratio

Computation and Language 2026-01-14 v1 Cryptography and Security Machine Learning

Abstract

Recent LLMs increasingly integrate reasoning mechanisms like Chain-of-Thought (CoT). However, this explicit reasoning exposes a new attack surface for inference-time backdoors, which inject malicious reasoning paths without altering model parameters. Because these attacks generate linguistically coherent paths, they effectively evade conventional detection. To address this, we propose STAR (State-Transition Amplification Ratio), a framework that detects backdoors by analyzing output probability shifts. STAR exploits the statistical discrepancy where a malicious input-induced path exhibits high posterior probability despite a low prior probability in the model's general knowledge. We quantify this state-transition amplification and employ the CUSUM algorithm to detect persistent anomalies. Experiments across diverse models (8B-70B) and five benchmark datasets demonstrate that STAR exhibits robust generalization capabilities, consistently achieving near-perfect performance (AUROC \approx 1.0) with approximately 42×42\times greater efficiency than existing baselines. Furthermore, the framework proves robust against adaptive attacks attempting to bypass detection.

Keywords

Cite

@article{arxiv.2601.08511,
  title  = {STAR: Detecting Inference-time Backdoors in LLM Reasoning via State-Transition Amplification Ratio},
  author = {Seong-Gyu Park and Sohee Park and Jisu Lee and Hyunsik Na and Daeseon Choi},
  journal= {arXiv preprint arXiv:2601.08511},
  year   = {2026}
}

Comments

16 pages, 5 figures