Fetching from the wire…
Security2026-07-29 · source-backed
arXiv 2607.25479 shows a malicious model provider can embed dormant steering logic in the architecture definition itself via a trigger-gated additive modification of an intermediate representation. No data poisoning, no control of downstream fine-tuning, no deployment-time prompt access. Absent the trigger it reduces to zero and clean utility is preserved. The recommendation is to audit the executable logic distributed with model artifacts, not just the weights. Almost nobody pulling third-party checkpoints runs that scan.
Each link below shares sources, entities, or timing with this story.
Shared entity: Architectural / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Architectural; reported by the same outlet (arxiv.org); overlapping topics (architectural, architecture, control).
Shared entity: Architectural / Same source domain / Shared topic / Earlier coverage
Both cover Architectural; reported by the same outlet (arxiv.org); overlapping topics (along, architectural).
Shared entity: VLM / Same source domain / Earlier coverage / Tension
Both cover VLM; reported by the same outlet (arxiv.org); earlier VLM coverage from 2026-06-29.
Shared entity: Almost / Shared topic / Earlier coverage / Tension
Both cover Almost; overlapping topics (architecture, model); earlier Almost coverage from 2026-05-14.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (access, control); pushes against this story (vs).
Reported by the same outlet (arxiv.org); overlapping topics (access, model); pushes against this story (but).
Same source domain / Shared topic / Downstream implication
Reported by the same outlet (arxiv.org); overlapping topics (artifact, model); traces where this leads (downstream).
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (access, model); pushes against this story (against).