Implementation · DiFR (Divergence From Reference)

Statistical tolerance leaves a covert channel

On this page

← All known flaws

SignificantDemonstrated attackOpen

Statistical schemes can put an upper bound on an adversary's covert bandwidth, but cannot close it 7. In the companion exfiltration study, the detector cut exfiltratable information to under 0.5% under benign prompt traffic. It did not cut it to zero 2. Its authors called the channel's size under adversarial prompts an open empirical question 2. An independent study attacked that detector, which uses the same Gumbel-margin statistic. An adversary who controls the prompts roughly doubled the bits leaked per token. Across six models, this cut the slowdown from 146–254 times under benign prompts to 60–118 times 9. The attack widens the exfiltration bound. It does not target DiFR's check that outputs match the declared configuration.

Sources: [7] · [2] · [9]

Search

Full search page