Imagine a restaurant where a junior sous-chef preps every plate and the head chef just gives a thumbs-up or thumbs-down before it goes out. The kitchen moves faster, but the sous-chef has different instincts — and some of the dangerous dishes slip through because the head chef is checking quality, not safety. That's speculative decoding. A small draft model generates candidate tokens, and the big target model verifies them. The speed gains are real. What nobody checked until now is whether the verification step also catches adversarial inputs — jailbreaks and prompt injections designed to make the model do things it shouldn't. The committed claim: lossy speculative decoding methods create a pronounced security-utility asymmetry, where attack success rates climb far faster than utility degrades, and a position-aware fix called SecureSD closes this gap. The paper reports that across multiple lossy speculative decoding variants, jailbreak and prompt injection attack success rates increase disproportionately — the security cost of approximation is much steeper than the utility cost. This is the first paper to measure this asymmetry systematically, and it's accepted at IEEE S&P 2027, the top security venue. The mechanism is clean and specific. The authors' theoretical analysis isolates the problem to early token positions — the first tokens generated by the draft model disproportionately shape the trajectory of the entire response. If the draft model accepts an adversarial framing in those early positions, the rest of the sequence follows that framing even after the target model takes over verification. Think of it like the first sentence of a conversation setting the tone: once you've conceded the premise, the rest follows. SecureSD applies a stricter verification criterion specifically to draft-model tokens at early decoding positions, relaxing as the sequence progresses. This is theory-guided, not heuristic — the paper derives why early positions matter and builds the solution around that insight. The result is improved security without meaningful degradation in efficiency or utility. The architecture family is standard speculative decoding (draft-then-verify), and SecureSD is a drop-in modification to the verification step, not a new model or training procedure. On the ladder: the baselines are the existing zoo of lossy speculative decoding methods — the paper compares across a wide range of them and shows the security-utility asymmetry is consistent. The comparison is against current speculative decoding SOTA, not stale baselines. The security benchmarks include jailbreak and prompt injection attack suites, and utility is measured on standard generation quality metrics. The authors are honest that their fix targets the specific failure mode they identified (early-token vulnerability) rather than claiming a universal security improvement. The integrity profile is strong for this type of work. IEEE S&P 2027 acceptance is a serious peer-review signal. The measurement study is large-scale and covers multiple attack types and decoding methods. The theoretical grounding means the fix isn't just empirical patching — there's a falsifiable mechanistic claim about where the vulnerability lives. The main limitation is that validation is simulation-based (LLM inference experiments), not adversarial red-teaming by independent teams. The obvious next experiment is adversarial adaptation: what happens when attackers specifically target SecureSD's position-aware verification? The authors demonstrate robustness against existing attacks, but an adaptive adversary who knows the early positions are more strictly verified could shift attack strategies toward later positions or use multi-turn approaches. This is likely being saved for follow-up work — it's the natural next paper in this line.