{"id":"https://openalex.org/W7123346177","doi":"https://doi.org/10.1109/dsa66321.2025.00022","title":"Security Threats in the Inference Phase of Large Language Models","display_name":"Security Threats in the Inference Phase of Large Language Models","publication_year":2025,"publication_date":"2025-11-24","ids":{"openalex":"https://openalex.org/W7123346177","doi":"https://doi.org/10.1109/dsa66321.2025.00022"},"language":null,"primary_location":{"id":"doi:10.1109/dsa66321.2025.00022","is_oa":false,"landing_page_url":"https://doi.org/10.1109/dsa66321.2025.00022","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 12th International Conference on Dependable Systems and Their Applications (DSA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Baolin Yan","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Baolin Yan","raw_affiliation_strings":["Institute of Software Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Software Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210128818","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5119399009","display_name":"Xiaotian Ai","orcid":null},"institutions":[{"id":"https://openalex.org/I125904092","display_name":"Shenyang Aerospace University","ror":"https://ror.org/02423gm04","country_code":"CN","type":"education","lineage":["https://openalex.org/I125904092"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaotian Ai","raw_affiliation_strings":["Shenyang Aircraft Design and Research Institute,Shenyang,China"],"affiliations":[{"raw_affiliation_string":"Shenyang Aircraft Design and Research Institute,Shenyang,China","institution_ids":["https://openalex.org/I125904092"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012005050","display_name":"Yuxi Ma","orcid":"https://orcid.org/0000-0001-5639-5214"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuxi Ma","raw_affiliation_strings":["Institute of Software Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Software Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210128818","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101741512","display_name":"Lingzhong Meng","orcid":"https://orcid.org/0000-0003-4463-2192"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lingzhong Meng","raw_affiliation_strings":["Institute of Software Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Software Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210128818","https://openalex.org/I19820366"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5122848186","display_name":"Guang Yang","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guang Yang","raw_affiliation_strings":["Institute of Software Chinese Academy of Sciences,Beijing,China"],"affiliations":[{"raw_affiliation_string":"Institute of Software Chinese Academy of Sciences,Beijing,China","institution_ids":["https://openalex.org/I4210128818","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210128818"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.82026129,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"93","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.21969999372959137,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.21969999372959137,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.186599999666214,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.11110000312328339,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6363999843597412},{"id":"https://openalex.org/keywords/taxonomy","display_name":"Taxonomy (biology)","score":0.48660001158714294},{"id":"https://openalex.org/keywords/abstraction","display_name":"Abstraction","score":0.4374000132083893},{"id":"https://openalex.org/keywords/automated-reasoning","display_name":"Automated reasoning","score":0.40369999408721924},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.3919999897480011},{"id":"https://openalex.org/keywords/natural-language","display_name":"Natural language","score":0.38350000977516174},{"id":"https://openalex.org/keywords/safer","display_name":"SAFER","score":0.37599998712539673},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.367000013589859}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.673799991607666},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6363999843597412},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5016999840736389},{"id":"https://openalex.org/C58642233","wikidata":"https://www.wikidata.org/wiki/Q8269924","display_name":"Taxonomy (biology)","level":2,"score":0.48660001158714294},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.4503999948501587},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.4374000132083893},{"id":"https://openalex.org/C195344581","wikidata":"https://www.wikidata.org/wiki/Q2555318","display_name":"Automated reasoning","level":2,"score":0.40369999408721924},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.3919999897480011},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.38350000977516174},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.382099986076355},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.37599998712539673},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.367000013589859},{"id":"https://openalex.org/C12174686","wikidata":"https://www.wikidata.org/wiki/Q1058438","display_name":"Risk assessment","level":2,"score":0.36239999532699585},{"id":"https://openalex.org/C539667460","wikidata":"https://www.wikidata.org/wiki/Q2414942","display_name":"Management science","level":1,"score":0.3215999901294708},{"id":"https://openalex.org/C2777363581","wikidata":"https://www.wikidata.org/wiki/Q15098235","display_name":"Harm","level":2,"score":0.3174000084400177},{"id":"https://openalex.org/C169900460","wikidata":"https://www.wikidata.org/wiki/Q2200417","display_name":"Cognition","level":2,"score":0.3075000047683716},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.3041999936103821},{"id":"https://openalex.org/C2780264999","wikidata":"https://www.wikidata.org/wiki/Q7445032","display_name":"Security domain","level":2,"score":0.29899999499320984},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29829999804496765},{"id":"https://openalex.org/C107327155","wikidata":"https://www.wikidata.org/wiki/Q330268","display_name":"Decision support system","level":2,"score":0.28279998898506165},{"id":"https://openalex.org/C2779439875","wikidata":"https://www.wikidata.org/wiki/Q1078276","display_name":"Natural language understanding","level":3,"score":0.2711000144481659},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2639999985694885},{"id":"https://openalex.org/C121822524","wikidata":"https://www.wikidata.org/wiki/Q5157582","display_name":"Computer security model","level":2,"score":0.26010000705718994},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.2551000118255615}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/dsa66321.2025.00022","is_oa":false,"landing_page_url":"https://doi.org/10.1109/dsa66321.2025.00022","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 12th International Conference on Dependable Systems and Their Applications (DSA)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6940543055534363,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"In":[0],"recent":[1],"years,":[2],"Large":[3],"Language":[4],"Models":[5],"(LLMs)":[6],"have":[7,23],"achieved":[8],"remarkable":[9],"advancements":[10],"in":[11],"natural":[12],"language":[13],"understanding,":[14],"contextual":[15],"modeling,":[16],"and":[17,38,41,71,99,124,141,147,151],"human-like":[18],"reasoning.":[19],"However,":[20],"these":[21,131],"capabilities":[22],"also":[24],"unveiled":[25],"a":[26,77,111],"spectrum":[27],"of":[28,80,88,103,114,130,149],"critical":[29],"security":[30,81,116],"vulnerabilities,":[31],"including":[32],"logical":[33],"inconsistencies":[34],"during":[35,84],"inference,":[36],"linguistic":[37],"semantic":[39],"disruptions,":[40],"entrenched":[42],"cognitive":[43],"biases.":[44],"Such":[45],"deficiencies":[46],"can":[47],"cause":[48],"LLMs":[49],"to":[50,61,126,136],"produce":[51],"inaccurate,":[52],"misleading,":[53],"or":[54],"even":[55],"harmful":[56],"outputs,":[57],"posing":[58],"significant":[59],"risks":[60],"high-stakes":[62],"applications":[63],"such":[64],"as":[65],"decision":[66],"support":[67],"systems,":[68],"legal":[69],"consultation,":[70],"medical":[72],"diagnostics.":[73],"This":[74],"paper":[75],"presents":[76],"systematic":[78],"analysis":[79],"threats":[82,107],"arising":[83],"the":[85,92,100,128,145],"inference":[86,93],"phase":[87],"LLMs.":[89],"By":[90],"examining":[91],"pipeline":[94],"across":[95],"its":[96],"distinct":[97],"stages":[98],"varying":[101],"levels":[102],"abstraction":[104],"at":[105],"which":[106],"manifest,":[108],"we":[109,120],"propose":[110],"comprehensive":[112],"taxonomy":[113],"potential":[115],"risk":[117],"factors.":[118],"Furthermore,":[119],"conduct":[121],"targeted":[122],"testing":[123],"validation":[125],"assess":[127],"impact":[129],"threats.":[132],"Our":[133],"study":[134],"aims":[135],"provide":[137],"both":[138],"theoretical":[139],"insights":[140],"practical":[142],"guidance":[143],"for":[144],"development":[146],"deployment":[148],"safer":[150],"more":[152],"reliable":[153],"LLM":[154],"systems.":[155]},"counts_by_year":[],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2026-01-14T00:00:00"}
