Model Equality Testing: Which Model is this API Serving?
Irena Gao, Percy Liang, Carlos Guestrin
Abstract
Users often interact with large language models through black-box inference APIs, both for closed- and open-weight models (e.g., Llama models are popularly accessed via Amazon Bedrock and Azure AI Studio). In order to cut costs or add functionality, API providers may quantize, watermark, or finetune the underlying model, changing the output distribution -- possibly without notifying users. We formalize detecting such distortions as Model Equality Testing, a two-sample testing problem, where the user collects samples from the API and a reference distribution and conducts a statistical test to see if the two distributions are the same. We find that tests based on the Maximum Mean Discrepancy between distributions are powerful for this task: a test built on a simple string kernel achieves a median of 77.4% power against a range of distortions, using an average of just 10 samples per prompt. We then apply this test to commercial inference APIs from Summer 2024 for four Llama models, finding that 11 out of 31 endpoints serve different distributions than reference weights released by Meta.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d82a42c2-5b7b-4d3a-8c7d-6aa704a5a343Cited by top-tier papers15
- Cost-of-Pass: An Economic Framework for Evaluating Language ModelsMehmet Hamza Erol, Batu El, Mirac Suzgun, Mert Yüksekgönül et al.ICLR 2026 · 40 citations
- Auditing Black-Box LLM APIs with a Rank-Based Uniformity TestXiaoyuan Zhu, Yaowen Ye, Tianyi Qiu, Hanlin Zhu et al.ICLR 2026 · 22 citations
- Real Money, Fake Models: Deceptive Model Claims in Shadow APIsYage Zhang, Yukun Jiang, Zeyuan Chen, Michael Backes et al.CCS 2026 · 15 citations
- Log Probability Tracking of LLM APIsTimothee Chauvin, Erwan Le Merrer, Francois Taiani, Gilles TredanICLR 2026 · 12 citations
- Token-Efficient Change Detection in LLM APIsTimothee Chauvin, Clément Lalanne, Erwan Le Merrer, Jean-Michel Loubes et al.ICML 2026 · 4 citations
Builds on6
- QLoRA: Efficient Finetuning of Quantized LLMsTim Dettmers, Artidoro Pagnoni, Ari Holtzman, Luke ZettlemoyerNeurIPS 2023 · 5,863 citations
- Efficient Memory Management for Large Language Model Serving with PagedAttentionWoosuk Kwon, Zhuohan Li, Siyuan Zhuang, Ying Sheng et al.SOSP 2023 · 1,016 citations
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- Enhancing Chat Language Models by Scaling High-quality Instructional ConversationsNing Ding, Yulin Chen, Bokai Xu, Yujia Qin et al.EMNLP 2023 · 95 citations
- On the Challenges of Using Black-Box APIs for Toxicity Evaluation in ResearchLuiza Pozzobon, Beyza Ermis, Patrick Lewis, Sara HookerEMNLP 2023 · 19 citations
Related papers
- Black-Box Detection of Language Model WatermarksThibaud Gloaguen, Nikola Jovanovic, Robin Staab, Martin T. VechevICLR 2025
- Statistical Hypothesis Testing for Auditing Robustness in Language ModelsPaulius Rauba, Qiyao Wei, Mihaela van der SchaarICML 2025
- User-side Model Consistency Monitoring for Open Source Large Language Models Inference ServicesQijun Miao, Zhixuan FangACL 2025 · 1 citation
- Model Provenance Testing for Large Language ModelsIvica Nikolic, Teodora Baluta, Prateek SaxenaNeurIPS 2025 · 20 citations
- Fundamental Limitations in Pointwise Defences of LLM Finetuning APIsXander Davies, Eric Winsor, Alexandra Souly, Tomek Korbak et al.NeurIPS 2025 · 13 citations
