CLASP: Defending Hybrid Large Language Models Against Hidden State Poisoning Attacks
arXiv cs.CL / 3/13/2026
📰 NewsIdeas & Deep AnalysisTools & Practical UsageModels & Research
Key Points
- CLASP defends hybrid SSM-based LLMs against Hidden State Poisoning Attacks by framing the mitigation as a token-level binary classification problem using an XGBoost classifier on block output embeddings.
- It achieves high detection performance in a realistic resume-scanning scenario: 95.9% token-level F1 and 99.3% document-level F1 on malicious tokens, with strong generalization to unseen attack patterns (96.9% doc-level F1 in leave-one-out; 91.6% doc-level F1 under structurally novel triggers).
- CLASP operates with modest resources—about 1,032 tokens/second and under 4 GB VRAM—making it a lightweight front-line defense that is independent of downstream models.
- The paper provides code and detailed results at the linked URL, illustrating a practical defense technique for SSM-based and hybrid architectures.
Related Articles

Astral to Join OpenAI
Dev.to

I Built a MITM Proxy to See What Claude Code Actually Sends to Anthropic
Dev.to

Your AI coding agent is installing vulnerable packages. I built the fix.
Dev.to

ChatGPT Prompt Engineering for Freelancers: Unlocking Efficient Client Communication
Dev.to

PearlOS. We gave swarm intelligence a local desktop environment and code control to self-evolve. Has been pretty incredible to see so far. Open source and free if you want your own.
Reddit r/LocalLLaMA