arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

同步对数几率调控:面向真实场景的隐写术

Synchronized Logit Steering: Real-world Steganography

Andrew Rufail, Aadi Dash, Onir Narahari, Ethan Mui, Mahi Gajare, Prakhar Tiwari, Shrija Makapothula, Nick Cui

arXiv 2608.14697首次发表:更新:

发表机构

Algoverse AI(Algoverse AI)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出同步对数几率调控(SLS),一种无需发送方与接收方共享相同提示上下文的确定性隐写方案,通过代理提示编码有效载荷,在多数据集上验证其低 KL 散度、高信息密度及强隐蔽性,实现实用隐蔽通信。

AI 中文摘要

大语言模型中的隐写术提供了一种在自然文本中嵌入隐藏消息的方式。现有的 token 级和对数几率级方法通常要求发送方和接收方共享完全相同的提示上下文,而在使用检索增强生成或专有系统指令的生产流程中,这种情况很少能得到保证。我们提出同步对数几率调控(Synchronized Logit Steering, SLS),这是一种确定性隐写方案,它通过从生成的输出本身推导代理提示来消除该依赖,使双方无需访问原始提示即可重建相同的对数几率分布。SLS 将有效载荷值编码为代理提示分布高熵区域内的 token 排名,我们还通过周期性循环和有效载荷突发扩展该方案以提升信息密度。在 ShareGPT、GSM8K 和 SWE-bench Verified 数据集上,我们发现当同步窗口达到 40 个 token 时,真实分布与代理提示分布之间的 KL 散度降至 0.5 nat 以下,且相对于贪心生成,SLS 编码不会显著破坏这种收敛性。我们还发现周期性突发变体达到每 token 0.20 比特,约为单有效载荷编码容量的 10 倍。柯尔莫哥洛夫-斯米尔诺夫检验进一步证实,SLS 输出在统计上难以与贪心生成区分开,证明通过大语言模型进行与提示无关的隐蔽通信既实用又隐蔽。

英文摘要

Steganography in large language models offers a way to embed hidden messages within natural-sounding text. Existing token and logit-level methods typically require the sender and receiver to share an identical prompt context, which is rarely guaranteed in production pipelines that use retrieval-augmented generation or proprietary system instructions. We introduce Synchronized Logit Steering (SLS), a deterministic steganographic scheme that eliminates this dependency by deriving a proxy prompt from the generated output itself, allowing both parties to reconstruct the same logit distribution without access to the original prompt. SLS encodes payload values as token ranks within high-entropy regions of the proxy prompt distribution, and we extend the scheme with periodic recurrence and payload bursts to scale information density. Across ShareGPT, GSM8K, and SWE-bench Verified, we show that the KL divergence between the true and proxy prompt distributions falls below 0.5 nats once the synchronization window reaches 40 tokens, and SLS encoding does not meaningfully disrupt this convergence relative to greedy generation. We also find that the periodic-burst variant achieves 0.20 bits per token, or roughly 10x the capacity of single-payload encoding. Kolmogorov-Smirnov tests further confirm that SLS outputs are statistically difficult to distinguish from greedy generations, demonstrating that covert, prompt-agnostic communication through LLMs is both practical and stealthy.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑