arXiv

Backdooring Masked Diffusion Language Models

Title: Exploiting Vulnerabilities in Masked Diffusion Language Models

Abstract

While masked diffusion language models (MDLMs) are rapidly gaining traction as a novel approach to text generation, their security during the training phase has received little attention. Traditional backdoor attacks designed for Gaussian diffusion models or autoregressive language models are not directly applicable to MDLMs, as these models operate on discrete state corruption and iterative denoising rather than the continuous noising or left-to-right prediction methods used by their counterparts. This paper introduces the first comprehensive investigation into training-time backdoor attacks targeting MDLMs.

We introduce SHADOWMASK, a novel attack vector that alters the forward corruption process of MDLMs. By substituting the standard all-mask terminal distribution with a trigger-mask mixture prior, SHADOWMASK establishes a specific denoising pathway that leads from trigger-corrupted states to targets defined by the attacker, all while maintaining the model’s clean denoising performance. To support this approach, we offer a rigorous mathematical framework that defines the backdoored forward process, calculates the reverse-time posterior, and establishes the continuous-time training objective.

Our empirical evaluations, conducted on DiT-based MDLMs and LLaDA-8B-Instruct across the WikiText-103, OpenWebText, and Alpaca datasets, demonstrate that SHADOWMASK achieves an attack success rate approaching 100%. The method significantly surpasses standard data poisoning techniques, maintains high utility for clean tasks, and remains effective even under full-model and parameter-efficient fine-tuning scenarios. Furthermore, the attack proves robust against several representative defensive measures.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...