Token-Efficient Change Detection in LLM APIs
Timothee Chauvin, Clément Lalanne, Erwan Le Merrer, Jean-Michel Loubes, Francois Taiani, Gilles Tredan
Abstract
Remote change detection in LLMs is a difficult problem. Existing methods are either too expensive for deployment at scale, or require initial white-box access to model weights or grey-box access to log probabilities. We aim to achieve both low cost and strict black-box operation, observing only output tokens. Our approach hinges on specific inputs we call Border Inputs, for which there exists more than one output top token. From a statistical perspective, optimal change detection depends on the model's Jacobian and the Fisher information of the output distribution. Analyzing these quantities in low-temperature regimes shows that Border Inputs enable powerful change detection tests. Building on this insight, we propose the Black-Box Border Input Tracking (B3IT) scheme. Extensive in vivo and in vitro experiments show that Border Inputs are easily found for the majority of tested endpoints, and achieve performance on par with the best available greybox approaches. B3IT reduces costs by 30× compared to existing methods, while operating in a strict black-box setting. *First author, method and experiments. †First author, theory and analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ef6e8102-9a2c-454f-82dd-75c25afe519eBuilds on7
- Locally private non-asymptotic testing of discrete distributions is faster using interactive mechanismsThomas Berrett, Cristina ButuceaNeurIPS 2020 · 41 citations
- Log Probability Tracking of LLM APIsTimothee Chauvin, Erwan Le Merrer, Francois Taiani, Gilles TredanICLR 2026 · 12 citations
- How Did the Model Change? Efficiently Assessing Machine Learning API ShiftsLingjiao Chen, Matei Zaharia, James ZouICLR 2022 · 5 citations
- Optimal Algorithms for Augmented Testing of Discrete DistributionsMaryam Aliakbarpour, Piotr Indyk, Ronitt Rubinfeld, Sandeep SilwalNeurIPS 2024 · 3 citations
- LLMmap: Fingerprinting for Large Language ModelsDario Pasquini, Evgenios M. Kornaropoulos, Giuseppe AtenieseUSENIX Security 2025
Related papers
- Transfer Learning without Knowing: Reprogramming Black-box Machine Learning Models with Scarce Data and Limited ResourcesYun-Yun Tsai, Pin-Yu Chen, Tsung-Yi HoICML 2020 · 115 citations
- BBox-Adapter: Lightweight Adapting for Black-Box Large Language ModelsHaotian Sun, Yuchen Zhuang, Wei Wei, Chao Zhang et al.ICML 2024 · 8 citations
- Auditing Black-Box LLM APIs with a Rank-Based Uniformity TestXiaoyuan Zhu, Yaowen Ye, Tianyi Qiu, Hanlin Zhu et al.ICLR 2026 · 22 citations
- Catch-22: On the Fundamental Tradeoff Between Detectability and Robustness in LLM WatermarkingKuheli Pratihar, Debdeep MukhopadhyayICML 2026
- Predicting the Performance of Black-box Language Models with Follow-up QueriesDylan Sam, Marc Finzi, Zico KolterNeurIPS 2025 · 10 citations
