The Mask Is Not the Model: Auditing Prefix Invariance in Attention, State-Space, and Hybrid Sequence Models
2026-08-24 • Machine Learning
Machine LearningArtificial Intelligence
AI summaryⓘ
The authors study a property called prefix invariance, which means a model's output at any position should not rely on future inputs. They developed a simple method involving two forward passes without extra training to detect exactly where this rule is broken. They show that just checking attention masks isn't enough because leaks can happen in other parts like scans or normalization. Their method successfully found all faults in 192 tests and even uncovered issues in two specific models, Zamba2 and Nemotron-H.
prefix invariancecausalityattention maskforward passnormalizationscansauditinginjected faultstransformersmodel checkpoints
Authors
Taebong Kim, Youngsik Hong, Minsik Kim, Sunyoung Choi, Jaewon Jang, Minseo Kim
Abstract
We formalize prefix invariance: representations at position t must not depend on future inputs. We give a lightweight audit, two forward passes, no training or gradients, that localizes exactly where causality breaks. Attention-mask inspection is incomplete: leaks can occur via scans or normalization despite correct masks. Across 192 injected-fault trials on eight checkpoints, mask inspection found none, while our audit localized all 192/192, also finding a defect in Zamba2 and Nemotron-H.