about
Logits of API-Protected LLMs Leak Proprietary Information (arxiv.org)
1 point by renonce on Mar 17, 2024 | hide | past | pdf | 1 comment on HN

In plain words: Because a big language model's output scores only occupy a narrow slice of all possible scores, a few API queries can reveal hidden details such as its internal width. Spending under $1000 on queries, this approach estimated GPT-3.5's hidden size at about 4096.

Abstract

Large language model (LLM) providers often hide the architectural details and parameters of their proprietary models by restricting public access to a limited API. In this work we show that, with only a conservative assumption about the model architecture, it is possible to learn a surprisingly large amount of non-public information about an API-protected LLM from a relatively small number of API queries (e.g., costing under $1000 USD for OpenAI's gpt-3.5-turbo). Our findings are centered on one key observation: most modern LLMs suffer from a softmax bottleneck, which restricts the model outputs to a linear subspace of the full output space. We exploit this fact to unlock several capabilities, including (but not limited to) obtaining cheap full-vocabulary outputs, auditing for specific types of model updates, identifying the source LLM given a single full LLM output, and even efficiently discovering the LLM's hidden size. Our empirical investigations show the effectiveness of our methods, which allow us to estimate the embedding size of OpenAI's gpt-3.5-turbo to be about 4096. Lastly, we discuss ways that LLM providers can guard against these attacks, as well as how these capabilities can be viewed as a feature (rather than a bug) by allowing for greater transparency and accountability.

Matthew Finlayson, Xiang Ren, Swabha Swayamdipta
arXiv:2403.09539 · cs.CL, cs.AI, cs.CR, cs.LG · submitted Mar 14, 2024 · updated Nov 8, 2024
abstract · pdf · html

add comment on HN

Highlight from this paper:

> Our empirical investigations show the effectiveness of our methods, which allow us to estimate the embedding size of OpenAI’s gpt-3.5-turbo to be about 4,096.

Discussion of the other paper is at https://news.ycombinator.com/item?id=39675735 but DeepMind seems to care more about helping their peer keep secrets and did not release GPT-3.5’s embedding size. Also the other paper is mentioned in Section 9 “Simultaneous discovery” of this paper in case anyone wonders.