SecondSourceJudgment rebuilt from primary sources
Research · Aug 29, 2026

Someone has demonstrated how to plant a backdoor through the memory layer while a model is in the middle of answering a question.

Model watch · This week (paper posted August 2026)

From the Aug 29, 2026 daily brief

Four researchers at Northeastern University, a research university in Boston, posted a paper called ROBBIN to the arXiv preprint server in August (the paper, August 2026; we came to it through a summary published by the semiconductor trade outlet Semiconductor Engineering on August 29, the summary, 08-29).

First, what Rowhammer is: a memory attack technique known for more than a decade. Hammering one row of memory at high speed flips bits in the physically adjacent rows, which means changing someone else's data in a place you have no permission to touch. What is new here is the order of operations. The usual approach designs a hardware-agnostic backdoor first, then works out how to realise it with bit flips, treating the flips that land badly as a side effect. This paper inverts that: it first measures where the target memory flips, then uses that map to decide which pages the model weights sit on. The abstract treats every flip as "an integral part of the attack design," and the authors claim the backdoor built this way holds up across devices.

⚠️ The honest boundaries in full: this is a preprint with no peer review; we read the abstract only, not the full paper, and have seen no independent replication; and the two abbreviations in the abstract — ASR and TA, which in this literature usually mean attack success rate and normal-task accuracy — carry no numbers at all, so how well this actually works has no answer today.

Subscribe free — first issue lands tomorrow morning

Just an email address, unsubscribe anytime. This is the only thing we ask of you.

More in this section