Token-Efficient Change Detection in LLM APIs
Timothee Chauvin, Clément Lalanne, Erwan Le Merrer, Jean-Michel Loubes, Francois Taiani, Gilles Tredan
摘要
Remote change detection in LLMs is a difficult problem. Existing methods are either too expensive for deployment at scale, or require initial white-box access to model weights or grey-box access to log probabilities. We aim to achieve both low cost and strict black-box operation, observing only output tokens. Our approach hinges on specific inputs we call Border Inputs, for which there exists more than one output top token. From a statistical perspective, optimal change detection depends on the model's Jacobian and the Fisher information of the output distribution. Analyzing these quantities in low-temperature regimes shows that Border Inputs enable powerful change detection tests. Building on this insight, we propose the Black-Box Border Input Tracking (B3IT) scheme. Extensive in vivo and in vitro experiments show that Border Inputs are easily found for the majority of tested endpoints, and achieve performance on par with the best available greybox approaches. B3IT reduces costs by 30× compared to existing methods, while operating in a strict black-box setting. *First author, method and experiments. †First author, theory and analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Locally private non-asymptotic testing of discrete distributions is faster using interactive mechanismsThomas Berrett, Cristina ButuceaNeurIPS 2020 · 被引用 41 次
- Log Probability Tracking of LLM APIsTimothee Chauvin, Erwan Le Merrer, Francois Taiani, Gilles TredanICLR 2026 · 被引用 12 次
- How Did the Model Change? Efficiently Assessing Machine Learning API ShiftsLingjiao Chen, Matei Zaharia, James ZouICLR 2022 · 被引用 5 次
- Optimal Algorithms for Augmented Testing of Discrete DistributionsMaryam Aliakbarpour, Piotr Indyk, Ronitt Rubinfeld, Sandeep SilwalNeurIPS 2024 · 被引用 3 次
- LLMmap: Fingerprinting for Large Language ModelsDario Pasquini, Evgenios M. Kornaropoulos, Giuseppe AtenieseUSENIX Security 2025
相关 Paper
- Transfer Learning without Knowing: Reprogramming Black-box Machine Learning Models with Scarce Data and Limited ResourcesYun-Yun Tsai, Pin-Yu Chen, Tsung-Yi HoICML 2020 · 被引用 115 次
- BBox-Adapter: Lightweight Adapting for Black-Box Large Language ModelsHaotian Sun, Yuchen Zhuang, Wei Wei, Chao Zhang 等ICML 2024 · 被引用 8 次
- Auditing Black-Box LLM APIs with a Rank-Based Uniformity TestXiaoyuan Zhu, Yaowen Ye, Tianyi Qiu, Hanlin Zhu 等ICLR 2026 · 被引用 22 次
- Catch-22: On the Fundamental Tradeoff Between Detectability and Robustness in LLM WatermarkingKuheli Pratihar, Debdeep MukhopadhyayICML 2026
- Predicting the Performance of Black-box Language Models with Follow-up QueriesDylan Sam, Marc Finzi, Zico KolterNeurIPS 2025 · 被引用 10 次
