AI 中文总结
本研究提出CacheTracer,利用前缀缓存侧信道测量LLM API转售商间的隐藏依赖关系,通过对39个转售商端点的测量发现了深度集中的缓存可达结构,验证了方法的可靠性与准确性。
AI 中文摘要
LLM API转售商已成为访问现代LLM服务的重要接入层,但多级转售形成了不透明的供应链:用户请求可能会经过未公开的上游转售商,每个转售商都可以检查或修改提示词和响应,从而引发生态系统层面的机密性和完整性风险。现有研究仅对单个转售商进行审计,几乎无法获取转售商之间隐藏依赖关系的可见性。我们提出CacheTracer,这是首个仅通过API实现的此类隐藏依赖关系测量方法。我们的核心见解是利用前缀缓存复用作为侧信道,通过缓存可达关系来测量依赖关系。CacheTracer通过两个原语实现这一见解:Flood通过一个端点填充新的缓存状态,Prove则探测另一个端点是否可以复用该缓存状态,同时排除探测产生的命中。我们随后使用CacheTracer对39个转售商端点开展了真实世界测量研究,在636个端点对之间发送了110万个API请求。我们的测量结果揭示了一种深度且集中的缓存可达结构:37.1%的被测端点对表现出共享缓存可达性,包含关系跨越7层,且某一缓存可达关系被至少31个其他节点包含。我们进一步发现,恢复的结构具有模型特异性。我们还通过真实世界一致性检查和受控实验评估了CacheTracer的有效性,结果表明其具有高可靠性和准确性。这些发现揭示了看似独立的API转售商之间存在大量隐藏依赖关系,这种深度且集中的依赖关系可能会产生较大的潜在影响范围,即共同上游路径上的机密性或完整性故障可能会影响多个下游转售商的用户。
英文摘要
LLM API resellers have become an important access layer to modern LLM services. However, multi-level resale creates an opaque supply chain: a user's request may traverse undisclosed upstream resellers, each of which can inspect or modify prompts and responses, inducing ecosystem-level confidentiality and integrity risks. Existing studies audit individual resellers, but provide little visibility into hidden dependencies across resellers. We present CacheTracer, the first API-only measurement of such hidden dependencies. Our key insight is to exploit prefix-cache reuse as a side channel to measure dependency via cache-reach relations. CacheTracer operationalizes this insight with two primitives: Flood populates fresh cache state through one endpoint, and Prove probes whether another can reuse it while excluding probe-created hits. We then conduct a real-world measurement study with CacheTracer on 39 reseller endpoints, sending 1.1 million API requests across 636 endpoint pairs. Our measurements reveal a deep, concentrated cache-reach structure: 37.1% of measured pairs exhibit shared cache reach, the containment order spans seven layers, and one cache reach is contained within at least 31 of other nodes. We further find that the recovered structure is model-specific. We also evaluate the validity of CacheTracer through both real-world consistency checks and controlled experiments. The results show its high reliability and accuracy. These findings reveal substantial hidden dependencies among seemingly independent API resellers. Such deep and concentrated dependencies can create a large potential blast radius, where a confidentiality or integrity failure along a common upstream path may affect users across multiple downstream resellers.