Implementation · AI 2040 inference-only verification stack

A recomputation family degrades against prompt-controlling adversaries

On this page

← All known flaws

SignificantDemonstrated attackOpen

The plan's companion page names DiFR among the recomputation schemes being tested. An independent study found that Gumbel-based inference verification, the family that includes Token-DiFR, leaks roughly twice as many bits per token when the adversary chooses prompts that disrupt the text's structure, across six models of 1 to 32 billion parameters. The slowdown it imposes on a hidden-signalling adversary falls from 146–254 times under benign prompts to 60–118 times. The attack weakens the bound on hidden information in outputs, which the plan relies on to keep undeclared results from leaving.

Sources: [2] · [6] · [7] · [1]

Search

Full search page