Implementation · DiFR (Divergence From Reference)
Technical detail
On this page
- The specification φ fixes the architecture and weights, numerical precision, sampling hyperparameters and the seed of the pseudorandom number generator 1.
- Token-DiFR works with Gumbel-Max sampling. From the shared seed, both parties derive the same Gumbel noise vector g. The verifier computes post-Gumbel scores z_i = l_i + T·g_i from its reference logits l and temperature T, and takes the token it would have chosen. It scores each claimed token by the logit-margin difference between the two tokens, clipped at a maximum. Scores are pooled per batch. A batch is flagged if the statistic exceeds a threshold set on a calibration set generated under φ on trusted hardware 1. Verification is one prefill pass over prompt plus output 1. The companion exfiltration paper gives a variant for inverse-probability-transform samplers 2.
- Activation-DiFR has both parties generate the same random orthogonal projection P from a shared seed. P is k by D, with k much smaller than D. The provider sends f = P·a for activation vector a, possibly only for every J-th token. The verifier checks the L2 distance to its own projection 1. For detecting FP8 KV-cache quantization on H200 GPUs, the authors report an AUC of at least 0.9999 with under 0.5 bytes per token. For Qwen3-30B-A3B on A100 GPUs, an AUC of 0.999 took 7.25 bytes per token, against 32 for TOPLOC 1.
- DiFR works with unmodified vLLM, which exposes per-request seeds as a standard sampling parameter 1.
- At temperature zero, Token-DiFR needs no seed synchronization. The verifier checks that the provider chose the most likely token at each position. The authors warn that such greedy spot checks are open to selective cheating. A provider could serve the declared model at temperature zero and a degraded one otherwise 1.