{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/analyzing-and-editing-inner-mechanisms-of","title":"Analyzing And Editing Inner Mechanisms Of Backdoored Language Models","arxiv_id":"2302.12461","date":"2023-02-24","proceeding":null,"authors":["Max Lamparth","Anka Reuel"],"abstract":"Poisoning of data sets is a potential security threat to large language models that can lead to backdoored models. A description of the internal mechanisms of backdoored language models and how they process trigger inputs, e.g., when switching to toxic language, has yet to be found. In this work, we study the internal representations of transformer-based backdoored language models and determine early-layer MLP modules as most important for the backdoor mechanism in combination with the initial embedding projection. We use this knowledge to remove, insert, and modify backdoor mechanisms with engineered replacements that reduce the MLP module outputs to essentials for the backdoor mechanism. To this end, we introduce PCP ablation, where we replace transformer modules with low-rank matrices based on the principal components of their activations. We demonstrate our results on backdoored toy, backdoored large, and non-backdoored open-source models. We show that we can improve the backdoor robustness of large language models by locally constraining individual modules during fine-tuning on potentially poisonous data sets. Trigger warning: Offensive language.","url_abs":"https://arxiv.org/abs/2302.12461v3","url_pdf":"https://arxiv.org/pdf/2302.12461v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"analyzing-and-editing-inner-mechanisms-of","repo_url":"https://github.com/maxlampe/causalbackdoor","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2302.12461","atlas_url":"https://app.syntology.ai/?focus=2302.12461","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.12461"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/maxlampe/causalbackdoor","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran":4,"ran_draft_wrong":1,"unverified":3},"by_repo_kind":{"official":{"samples":8,"ran":5,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"d567362597985d0f","entry":"create_testclean_sample","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/create_poison.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/create_poison.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"d567362597985d0f"}},{"code_sha256_prefix":"920b394e7ad80c53","entry":"hierarchical_subsequence","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/nethook.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/nethook.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"920b394e7ad80c53"}},{"code_sha256_prefix":"70f6ab8bde55420e","entry":"recursive_copy","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/nethook.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/nethook.py","link_basis":"harvester_set","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"70f6ab8bde55420e"}},{"code_sha256_prefix":"784b4fa0a17f1811","entry":"replace_modules","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/tools.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/tools.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"784b4fa0a17f1811"}},{"code_sha256_prefix":"440ff98c2b1ae1aa","entry":"subsequence","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/nethook.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/nethook.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"440ff98c2b1ae1aa"}},{"code_sha256_prefix":"3ef9c8a5a1c4a15b","entry":"create_backdoor_sample","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/create_poison.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/create_poison.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"3ef9c8a5a1c4a15b"}},{"code_sha256_prefix":"853f6b235400c369","entry":"create_testtrigger_sample","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/create_poison.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/create_poison.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"853f6b235400c369"}},{"code_sha256_prefix":"63c2930e616bf8a5","entry":"zeroresidual_modules","repo":"maxlampe/causalbackdoor","repo_kind":"official","path":"src/rome/tools.py","file_url":"https://github.com/maxlampe/causalbackdoor/blob/HEAD/src/rome/tools.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"63c2930e616bf8a5"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}