arXiv:2602.08214cs.AIcs.CR2026-02被引 3

提出新型资源耗尽攻击,利用反思机制漏洞让大模型推理失控。

RECUR: Resource Exhaustion Attack via Recursive-Entropy Guided Counterfactual Utilization and Reflection

  • 通过递归熵量化反思过程的资源风险,发现推理本身存在安全隐患。
  • 攻击使输出长度增加11倍,吞吐量下降90%,实测效果显著。
  • 适合研究模型安全、推理效率及对抗攻击的开发者与研究人员。

大型推理模型(LRMs)通过显式推理处理复杂任务,但其长上下文需求导致资源消耗巨大。已有研究显示,恶意输入可触发冗余推理,暴露资源耗尽漏洞。然而,推理中的反思环节仍被忽视,尽管它可能导致过度反思并消耗大量计算资源。本文提出递归熵(Recursive Entropy)来量化反思环节的资源消耗风险,揭示推理过程本身的安全隐患。基于此,我们设计了RECUR攻击:通过构建反事实问题,验证模型内在缺陷。实验表明,在正常推理下,递归熵呈明显下降趋势;而RECUR破坏该趋势,使输出长度最高增加11倍,吞吐量降低90%。本工作为鲁棒推理提供了新视角。

原文摘要 · Abstract (English)

Large Reasoning Models (LRMs) employ reasoning to address complex tasks. Such explicit reasoning requires extended context lengths, resulting in substantially higher resource consumption. Prior work has shown that adversarially crafted inputs can trigger redundant reasoning processes, exposing LRMs to resource-exhaustion vulnerabilities. However, the reasoning process itself, especially its reflective component, has received limited attention, even though it can lead to over-reflection and consume excessive computing power. In this paper, we introduce Recursive Entropy to quantify the risk of resource consumption in reflection, thereby revealing the safety issues inherent in inference itself. Based on Recursive Entropy, we introduce RECUR, a resource exhaustion attack via Recursive Entropy guided Counterfactual Utilization and Reflection. It constructs counterfactual questions to verify the inherent flaws and risks of LRMs. Extensive experiments demonstrate that, under benign inference, recursive entropy exhibits a pronounced decreasing trend. RECUR disrupts this trend, increasing the output length by up to 11x and decreasing throughput by 90%. Our work provides a new perspective on robust reasoning.

模型安全推理攻击资源耗尽

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。