arXiv Machine Learning

Your "Pro" LLM Subscription May Actually Be "Free": Exposing Fingerprint Spoofing Risks in LLM Inference Services

arXiv:2606. 16100v1 Announce Type: cross Abstract: As Large Language Model (LLM) APIs become ubiquitous, users increasingly rely on black-box fingerprinting to verify that providers are serving the advertised premium models.

arXiv Machine Learning
Jul 14

One Token Is Enough: Fingerprinting and Verifying Large Language Models from Single-Token Output Distributions

arXiv:2607. 10252v1 Announce Type: cross Abstract: Large language models (LLMs) are increasingly consumed through opaque serving chains - API aggregators, resellers, and inference providers - in which the client has no technical means to confirm that the model answering is the model advertised, and recent audits show that a substantial fraction of commercial endpoints deviate from the vendor's reference weights.

By Tomas Bruckner
arXiv AI
Sep 10

D-ADD: An Effective Plug-In for Defending Against Model Stealing

The paper introduces D-ADD, a plug‑in defense for image classification models that protects against model‑stealing attacks. It uses a non‑parametric detector called Account‑aware Distribution Discrepancy (ADD) to identify malicious queries by modeling each class as a multivariate normal distribution and computing weighted distribution discrepancies. With an enhanced version ADD$^+$ that handles domain shifts and combined with random‑based prediction poisoning, D-ADD offers strong protection while minimally affecting benign users in both soft‑ and hard‑label settings.

By Jian-Ping Mei, Weibin Zhang, Jie Chen, Xuyun Zhang, Tiantian Zhu