Mechanism · Sampled inference recomputation
Tolerance for numerical noise leaves a covert channel
On this page
Schemes that accept approximate matches can put an upper bound on an adversary's covert bandwidth, but they cannot close the channel 5. The weight-exfiltration detector cut exfiltratable information to under 0.5%, not to zero, on a 30-billion-parameter mixture-of-experts model under benign prompt traffic 1. Its authors called the channel's size under adversarial prompts an open empirical question 1. An independent study showed that an adversary who controls the prompts roughly doubles the bits leaked per token. Across six models, that cut the slowdown from 146–254 times under benign prompts to 60–118 times 16. The attack widens the exfiltration bound. It does not target the check that outputs match the declared model 16.