攻击者可利用级联架构弱点,让轻量模型误判,引发性能与效率双重崩溃。
When Efficiency Backfires: Cascading LLMs Trigger Cascade Failure under Adversarial Attack

- 设计新攻击框架,通过优化后缀诱导轻量模型误判
- 实测显示攻击使系统效率下降超60%,准确率大幅降低
- 适合关注大模型安全与部署风险的研究者
大型语言模型级联系统通过轻量模型处理简单请求,复杂任务再升级至强大模型,以平衡效率与性能,降低计算成本和延迟,适用于大规模部署。然而,这种级联结构引入了新的安全漏洞:前端轻量模型和内部决策机制构成新的攻击面。本文首次揭示此类系统易受针对性对抗攻击,破坏性能与成本优势。提出新型攻击框架,基于级联依赖关系,对对抗后缀进行约束性序列协同优化,可同时利用轻量模型与决策机制,实现对系统成本效益与准确性的可控降级。该方法适应不同攻击能力,影响远超针对单模型的攻击。在多个数据集和代表性级联系统上验证了攻击的可行性和严重性。研究警示需高度重视级联系统的安全性,并呼吁关注其固有的系统性风险。
原文摘要 · Abstract (English)
Large Language Model (LLM) cascade systems are designed to balance efficiency and performance by processing queries with lightweight models while selectively escalating complex cases to more powerful ones. Such systems seek to reduces computational cost and latency while maintaining task performance, making it an appealing choice for large-scale deployment. However, the cascade design introduces new vulnerabilities through an expanded attack surface: the inclusion of lightweight front-end models and internal decision mechanisms introduces new weaknesses. In this work, we present the first study demonstrating that LLM cascade systems are susceptible to targeted adversarial manipulation, which disrupts both performance objectives and the intended cost advantages of the cascade design. We propose a novel attack framework that employs constrained sequential collaborative optimization of adversarial suffix under cascade dependencies, enabling simultaneous exploitation of lightweight models and decision mechanisms. This framework adapts to adversaries with varying capabilities, inducing controllable degradation in both cost-efficiency and accuracy. Unlike prior attacks targeting standalone models, our approach strategically leverages the cascade structure to achieve significantly stronger impact. Extensive experiments across diverse datasets and representative LLM cascade systems validate the practicality and severity of this attack. Our findings highlight the urgent need to rigorously scrutinize the security of LLM cascade systems and call for broader attention to the systemic risks inherent in such designs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。