3/5 SSMs are recurrent, each token depends on previous state. Mamba decode reads state → updates it. Misclassified request reads garbage → propagates recursively through all tokens. Attention writes K/V first, then attends. Safe even if misclassified.
SSM Recurrence Security: Mamba State Propagation vs Attention Safety
By
–
Leave a Reply