cs.CROct 1, 2026

MOMAT: Mixture of Multiple Atlases for Low-Power Jailbreak Defense of Quantized LLMs

Authors: Boyang Li, Bingyu Shen, Weihao Hong, Zhiyuan Jiang, Xinlei Guan, Yan Ma, Miles Q. Li, Yi Sheng, +1 more

Organizations: Department of Computer Science, Kean University, 1000 Morris Ave, Union, 07083, NJ, USA · Department of Computer Science and Engineering, University of Notre Dame, 257 Fitzpatrick Hall of Engineering, Notre Dame, 46556, IN, USA · McGill University, 845 Sherbrooke Street, Montréal, H3A 0G4, Québec, Canada · Department of Computer Science and Engineering, University of South Florida, 4202 E Fowler Ave, Tampa, 33620, FL, USA · Department of Computing Sciences, Villanova University, 800 E Lancaster Ave, Villanova, 19085, PA, USA

Abstract

Quantized large language models are increasingly deployed on edge devices for their low latency and energy efficiency. However, model quantization weakens alignment safeguards, leaving qLLMs (quantized large language models) highly vulnerable to jailbreak attacks. To address this challenge, we present MOMAT (Mixture of Multiple Atlases), a hardware-enhanced safety framework that combines structured knowledge retrieval with low-power defense acceleration. Each atlas represents a semantic cluster of harmful or benign sample sets and policy templates, enabling domain-localized Retrieval-Augmented Generation guarding that mitigates the curse of dimensionality and the resulting semantic sparsity problem in large, heterogeneous safety databases. MOMAT retrieves top-kk similarity features from all atlases for each prompt and evaluates them using a lightweight MoE (Mixture of Experts) detector, while a CiM (Compute-in-Memory)-accelerated similarity engine performs fast, low-power atlas-local retrieval. MOMAT's CiM-based retrieval accelerates a 100-query batch from 15,052.44 ms to 3,207.21 ns (a 4.69×106×4.69 \times 10^6\times speedup) and reduces energy from 8.1×1078.1 \times 10^7 μμJ to 3.32 μμJ, yielding an approximately 2.5×105×2.5 \times 10^5\times energy reduction over DRAM-based (Raspberry Pi) baselines. Red-team evaluations across standard benchmarks show that MOMAT matches the defense performance of state-of-the-art methods while avoiding benign overkill and providing substantial efficiency gains, demonstrating that CiM-based modular defenses can make edge-deployed qLLMs both safer and more energy-efficient. We will release the full 223.2k-sample dataset to foster future research.

Figures & tables

Explore similar work

CardsList
  1. FlipGuard: Defending Large Language Models Against Quantization-Conditioned Backdoor Attacks

    Jun 27, 2026Aoying Zheng, Anqi Du, Zizhuang Deng +1Large Language Model BackbonesLLM Defense Mechanisms

  2. Alignment Collapse Under KV Cache Quantization: Diagnosis and Mitigation

    Jun 1, 2026Bruce Changlong Xu, Adarsh Kumarappan, Mu ZhouKey-Value Cache QuantizationLarge Language Model Quantization