{"data":{"id":"d966422b-6742-48ca-8502-be66792fd4d8","title":"Speedbumps: Rejection Attacks on Speculative Decoding","summary":"Researchers study Speculative Rejection Attacks (SRAs), which append an adversarial suffix to attacker-controlled content so that draft and target models disagree more often in speculative decoding. Two attacks, Speedbump-P and Speedbump-D, optimise the expected length of the accepted speculative prefix, and in some cases slow inference below autoregressive decoding. The suffixes stay effective under sampling and transfer across drafters or target models sharing a drafter, showing the draft-target interaction is a realistic attack surface for inflating inference costs.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://arxiv.org/abs/2610.10929v1","publishedAt":"2026-10-07T21:35:01.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"low","attackType":["denial_of_service"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["large language models","speculative decoding"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-07T21:35:01.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null}}