Mechanism · Model identity attestation

Recomputation depends on trusted logging and randomness, and its tolerance leaves a covert channel

On this page

← All known flaws

SignificantDemonstrated attackOpen

The recomputation variant assumes that every input, output and seed is logged correctly, and that the attacker can neither predict nor manipulate which messages are sampled for verification. Legitimate nondeterminism concentrates at a few token positions, and slow leaks within the tolerated slack remain possible 4. An independent study showed that an adversary who controls the prompts roughly doubles the bits leaked per token, reducing the exfiltration slowdown from 146–254 times under benign prompts to 60–118 times. The attack targets the exfiltration bound, not the check that outputs match the declared model 5.

Sources: [4] · [5]

Search

Full search page