← Back to feed
PublicationsJun 1183% confidenceConfidence 83% — the share of independent, credible sources corroborating the core facts.

Researchers Discover Grammar-Constrained Decoding Can Be Exploited to Jailbreak LLMs into Generating Malicious Code

Center 100%
1 source

Researchers have identified a new attack method, dubbed CodeSpear, that exploits Grammar-Constrained Decoding (GCD) — a technique designed to improve code reliability — to bypass safety guardrails in large language models and generate malicious code. GCD is widely used to enforce syntactic validity in LLM-generated code, but the study shows that applying even a benign grammar constraint can serve as an effective jailbreak vector. The findings highlight a fundamental security risk in a broadly adopted reliability tool and prompted the researchers to propose a countermeasure called CodeShield.

A preprint submitted to arXiv reveals that Grammar-Constrained Decoding (GCD), a technique commonly used to ensure LLMs produce syntactically valid code, can paradoxically be weaponized as a jailbreak attack surface. The attack, called CodeSpear, works by applying a benign code grammar constraint that effectively suppresses natural-language safety refusals and steers the model toward generating malicious code. Experiments conducted across 10 popular LLMs and 4 benchmarks showed CodeSpear outperformed existing jailbreak baselines, increasing attack success rates by more than 30 percentage points on average. To counter this vulnerability, the researchers developed CodeShield, a safety alignment approach that trains models to produce 'honeypot' code under GCD — output that is semantically harmless and structurally varied enough to resist grammar-tightening suppression — while preserving natural-language refusals when applicable. CodeShield was shown to restore safe behavior under CodeSpear attacks without significantly degrading the model's legitimate utility. The authors argue their findings expose a fundamental and underappreciated security risk in GCD and call for broader scrutiny of its security implications as LLM-based code generation becomes more prevalent.

What's missing

The paper is a preprint and has not yet undergone peer review. Key open questions include whether CodeShield generalizes to GCD implementations and grammar formats not tested in the study, whether adversaries could adapt grammar constraints to circumvent CodeShield's honeypot mechanism, and how the attack performs against models with reinforcement learning from human feedback (RLHF) safety tuning beyond the 10 LLMs evaluated.

What different sources said

  • Grammar-Constrained Decoding Can Jailbreak LLMs into Generating Malicious Code

Related

PublicationsConfidence 78% — the share of independent, credible sources corroborating the core facts.

Gut Bacteria Enzyme Found to Break Down Heat-Processed Food Compounds, Producing Novel Biogenic Amines

Researchers have discovered that an enzyme in common gut bacteria can degrade N-epsilon-carboxymethyllysine (CML), a compound formed during thermal food processing, producing previously unknown biogenic amines. The enzyme, ornithine decarboxylase SpeC from enterobacteria, acts on CML and related modified lysine derivatives through a low-level 'underground' catalytic activity. This finding suggests a previously unrecognized communication axis between thermally processed dietary compounds and gut microbial physiology, with potential implications for host health.

1 sourceJun 13
PublicationsConfidence 78% — the share of independent, credible sources corroborating the core facts.

Full-Length Gene Sequencing Reveals Two Distinct Bacterial Communities in Black-Legged Ticks Expanding Into Canada

Researchers used Oxford Nanopore full-length 16S rRNA gene sequencing to characterize the microbiome of Ixodes scapularis black-legged ticks collected in Nova Scotia, Canada, distinguishing between tick-adapted bacteria and environmentally acquired bacteria. The study comes as I. scapularis — the primary vector of Lyme disease — is rapidly expanding northward into Canada due to climate change. The findings suggest that environmentally derived bacteria in tick microbiomes are not mere contamination, which has implications for how tick microbiome data is collected and interpreted across surveillance studies.

1 sourceJun 13
PublicationsConfidence 78% — the share of independent, credible sources corroborating the core facts.

Study Identifies Metabolic Link Between Cell Envelope Stress and Biofilm Formation in Bacteria

Researchers have discovered that the metabolite acetyl-CoA directly inhibits enzymes that degrade the bacterial signaling molecule c-di-GMP, connecting cell envelope biosynthesis stress to biofilm formation in Pseudomonas aeruginosa. The study found that sub-inhibitory concentrations of antibiotics targeting early peptidoglycan biosynthesis — but not other antibiotic classes — elevate c-di-GMP levels by reducing phosphodiesterase activity, with acetyl-CoA competing for the enzyme active site. Because the relevant enzyme domain is broadly conserved across bacterial species, this checkpoint mechanism may be widespread and could have implications for understanding antibiotic-induced biofilm responses.

1 sourceJun 13