Preliminary research
Chat-template backdoors: systematic evaluation and agentic impact
Inference-Time Backdoors via Chat Templates: From LLM Supply Chains to Agentic System Compromise
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Poisoned chat templates insert privileged instructions without changing model weights. This 2026 study extends a July 2025 disclosure with comparative model and runtime evaluation; its May revision adds agent experiments, although complete agent artifacts were not located during review.
Record
- Document
- Inference-Time Backdoors via Chat Templates: From LLM Supply Chains to Agentic System Compromise
- Researcher
- Ariel Fogel, Omer Hofman, Eilon Cohen and Roman Vainshtein
- Published by
- arXiv
- Date
- Format
- Whitepaper
- Topic
- Injection
In the archive
Related sources
- BadTemplate: A Training-Free Backdoor Attack via Chat Template Against Large Language Models Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Ariel Fogel, Omer Hofman, Eilon Cohen and Roman Vainshtein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .