Implementation · DiFR (Divergence From Reference)

Sources

On this page
  1. BA. Karvonen et al. (2025). DiFR: Inference Verification Despite Nondeterminism. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: method, specification, experiments, results, comparison with TOPLOC and distributional methods, provider case study, deployment considerations, limitations, speculative-decoding sketch · abstract; §2-3; §5; §5.1; §6.2; Table 1; §7.2-7.4; Appendix D; Appendix F
  2. BR. Rinberg et al. (2025). Verifying LLM Inference to Detect Model Weight Exfiltration. arXiv. Source recordSupports: companion security game and exfiltration results using Token-DiFR estimators; adversarial prompts an open question · abstract; contributions; §4; §5.3
  3. BA. Karvonen (2025). adamkarvonen/difr (GitHub repository). GitHub. Source recordSupports: public code, licence, vLLM and API modes · README
  4. CAmodo Design (2026). Scaling Recomputation Inference Verification. Amodo Design. Source recordSupports: independent prototype, scale and vLLM sampling mismatch · whole note
  5. BAmodo Design (2026). Amodo-Design/Inference-Recomputation-Prototype (GitHub repository). GitHub. Source recordSupports: prototype code, research code not production software; modified copy of the difr library · README
  6. CAmodo Design (2026). An Inference Verification Prototype — Stage 1. Amodo Design. Source recordSupports: first Amodo prototype reusing the DiFR library; tests against two LoRA fine-tuning attacks on 8×H100; pass-rate gap; short answers; limits of the tests · setup; results; limitations
  7. BN. Cankaya (2026). Bit-Exact AI Inference Verification Without Performance Tradeoffs. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: limits of statistical verification · §1
  8. CAmodo Design (2026). AI 2040 Plan A — Verification SITREP. Amodo Design. Source recordSupports: status of red-teaming · status items
  9. BN. Kezins (2026). Adversarial Entropy Inflation Against Gumbel-Based Inference Verification. arXiv. Source recordSupports: independent attack on a weight-exfiltration detector built on the Token-DiFR Gumbel-margin statistic; scope limited to the exfiltration bound · abstract; introduction

Search

Full search page