From Role Prompt to Infinite Thinking: Exploiting Persona Conditioning for Inference Cost Attacks in LLMs
Zhiyi Mou, Wangze Ni, Tianfang Xiao, Haoyang LI, Chen Jason Zhang, Hanzhi Ma, Yang Bai, Zhibo Wang, Kui Ren
cs.CR
Submitted: 2026-07-28
Comments: 17pages
License: http://creativecommons.org/licenses/by/4.0/
The gist: LLMs are increasingly deployed in real-world applications, making inference efficiency and service reliability critical concerns due to their substantial computational costs.
Terminology
Abstract
LLMs are increasingly deployed in real-world applications, making inference efficiency and service reliability critical concerns due to their substantial computational costs. However, the autoregressive generation mechanism of LLMs enables malicious prompts to manipulate generation behaviors, inducing excessive token generation that amplifies computational consumption and threatens service efficiency. Existing methods mainly rely on adversarial suffixes or explicit extension instructions, which introduce detectable behaviors and limit their applicability. In this paper, we reveal a previously unexplored vulnerability caused by persona consistency in LLMs, where models maintain assigned roles and reproduce corresponding behaviors even when they result in inefficient reasoning and excessive generation. Based on this observation, we propose RolePlay, a task-aware dynamic persona alignment framework that constructs adaptive personas to naturally induce inefficient yet semantically coherent behaviors for inference cost amplification. Extensive experiments across multiple LLMs and diverse task datasets demonstrate that RolePlay consistently outperforms existing inference extension methods, achieving an average token amplification of up to 7.64 times and a maximum token amplification ratio of 207.64 times. Our findings identify persona conditioning as a new attack surface for LLM inference efficiency and offer a new perspective on computational cost amplification.
Sources
- Detecting Language Model Attacks with Perplexity
- Evaluating Large Language Models Trained on Code
- Training Verifiers to Solve Math Word Problems
- Measuring Massive Multitask Language Understanding
- Measuring Mathematical Problem Solving With the MATH Dataset
- Baseline Defenses for Adversarial Attacks Against Aligned Language Models
- OverThink: Slowdown Attacks on Reasoning LLMs
- ThinkTrap: Denial-of-Service Attacks against Black-box LLM Services via Infinite Thinking
- OpenAI GPT-5 System Card
- Qwen3.5-Omni Technical Report
- Inducing Overthink: Hierarchical Genetic Algorithm-based DoS Attack on Black-Box Large Language Reasoning Models
- DeepSeek-V4: Towards Highly Efficient Million-Token Context Intelligence
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs