SpecTrojan: Adversarial Specification Validation via Evil Twin Synthesis
Ojas Marathe · Team Spectacular
Submitted to The Secure Program Synthesis Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
SpecTrojan is a spec-validation tool that inverts the traditional input-space search: given a candidate specification, an attacker LLM synthesizes an "Evil Twin" — an alternative implementation that satisfies the spec yet diverges from the reference on intent-bearing inputs. A successful twin is an artifact-level proof that the spec is too weak. On a Bio Honeypot (an LLM-written spec for a sequence-screening predicate), SpecTrojan synthesized 16 evil twins in 60 seconds, including a trivial return True that passes verification while admitting every threat-bearing input. The system also includes an attack-to-strengthening loop that auto-proposes and mechanically verifies spec repairs, and metamorphic spec testing that catches syntax-overfit specs.
Reviews
Evil twins to show naivety is powerful. Would be useful to test fully on a bigger set, and focus more on showing robustness.
The reframe is novel: search the implementation space and synthesize a whole spec-satisfying alternative, so a surviving twin is an artifact-level proof that the specification is too weak. The system is broad and well-built: a twin synthesizer, two baselines, metamorphic testing, and a strengthening loop whose verifier catches every broken LLM repair while a hand-crafted control passes, with an unusually honest robustness section. Caveats. The headline target is a constructed honeypot, and twin counts are stochastic (sixteen one run, zero the next), so foreground the stable binary signal, whether any twin is found, over the counts. A twin only satisfies the spec across eighty Hypothesis samples, so satisfaction is probabilistic. The capability matrix is rhetorically circular, its rows defined as what the method does, so drop the strictly-subsumes claim. And the central comparison figure has a truncated caption with several mangled identifiers, worth a cleanup pass.
Read full reviewShow less
Cite this project
@misc{marathe2026spectrojan,
title = {{SpecTrojan: Adversarial Specification Validation via Evil Twin Synthesis}},
author = {Ojas Marathe},
year = {2026},
month = may,
note = {Submitted to The Secure Program Synthesis Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/spectrojan-adversarial-specification-validation-via-evil-twin-synthesis-qm6i}},
url = {https://apartresearch.com/sprints/projects/spectrojan-adversarial-specification-validation-via-evil-twin-synthesis-qm6i}
}More from The Secure Program Synthesis Hackathon
- View project: Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Lida Safety
Specifications for real systems do not exist as one-shot artifacts: the user's intent emerges as they discover edge cases, rewrite drafts, and react to failing tests. We present an iterative pipeline that takes this …
- View project: AgentSpecGap
AgentSpecGap
solo-team
This prototype extracts rules from system prompts, tool descriptions, and runtime config. Rules are classified into one of interface validation, authorization check, workflow ordering validation, runtime validation, …
- View project: SpecGap Arena
SpecGap Arena
Obligation Cartographers
SpecGap Arena is a benchmark and framework that exposes how incomplete specifications let plausible but incorrect code pass public tests. It synthesizes missing semantic obligations (security boundaries, invariants, …