AI Heroes Logo AI Heroes
AI News Image
Jul 25, 2026
Critical LLM Models & Research

Mark Russinovich's new research reveals a critical flaw: LLM backdoors can now be triggered by the mere *position* of input tokens, not just specific words. It suggests that AI defenses aren't just being bypassed by sophisticated text, but by the model's fundamental architecture itself. Are we trusting systems whose foundations are vulnerable to invisible, structural manipulation?

  • Backdoors have shifted from content-based triggers (keywords) to structural, positional triggers.
  • The trigger is semantically and visibly invisible, bypassing traditional text-scanning security measures.
  • Attacks can be activated by simple length conditions, leading to highly stealthy and subtle vulnerabilities.
  • Contextual manipulation allows malicious behavior (like data leaks) to activate naturally during multi-turn, routine conversations.
Why it matters: This breakthrough signifies that AI security must fundamentally shift its focus from analyzing *what* the input says (the content) to analyzing *how* the input is structured and processed (the architecture).