arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

先封印,再采样:从 GPT-2 到 70B 的可验证 LLM 推理的分层采样证明

Seal, Then Sample: Sampled Layerwise Proofs for Verifiable LLM Inference from GPT-2 to 70B

Youki Lim, Sam Yong

arXiv 2609.27367首次发表:更新:

AI 中文总结

提出分层采样证明(SLP)协议,通过承诺边界激活并仅证明验证者选定的块子集,实现从 GPT-2 到 70B 模型的可验证 LLM 推理,显著降低证明成本与时间。

AI 中文摘要

验证外包的语言模型推理需要一个精确定位的计算过程以及服务提供商能够负担得起的审计成本。我们提出了分层采样证明(SLP),这是一种协议和原型,它承诺推理轨迹中每个块(chunk)的边界激活值,在抽取任何挑战之前吸收所有承诺,然后证明验证者选定的块子集以及绑定提示(prompt)和答案的块。审计覆盖率成为一组承诺上的运行时参数:在 TinyLlama-1.1B 轨迹上,证明 47 个块中的 7 个块所需的时间仅为证明全部 47 个块的 22.0%,证明大小仅为后者的 6.8%。由于证明成本主要由权重而非令牌(token)决定,SLP 在块对角因果掩码下将并发请求打包到一条轨迹中,并将每个请求的提示和答案绑定到其槽位。十二个打包请求在 181.9 秒内完成证明,比按测量的单证明成本计算的十二个独立证明快 6.5 倍;一个模拟服务以每个请求 30.6 秒的速度证明十二个请求,每个请求验证仅需 0.6 秒,并能拒绝被篡改的答案。磁盘支持的整数权重和流式多项式承诺使得单个 Llama-2-70B 运行能在 2 TB CPU 主机上完成:封印 163 个块,证明其中 5 个,生成 4.34 MiB 的证明耗时 1,259 秒,验证在 46.3 秒内完成且无需权重。被证明的对象是一个定点规范模型;我们将严重的保真度损失追溯到残差流位宽,并用一个 LLM 感知的观察器修复它,在 334,705 个 WikiText-2 测试位置上测量到与浮点参考的 84.8-84.9% 的 argmax 一致性。局限性被精确地陈述:保证仅覆盖被证明的块,在 70B 设置中一个固定的无效块被覆盖的概率为 3/161,仅清单式的 Fiat-Shamir 调度可能以每次尝试 12.5 毫秒的速度被破解,需要外部排序的挑战,所有测量均使用测试参考字符串。

英文摘要

Verifying outsourced language-model inference requires a precisely identified computation and an audit whose cost a service can afford. We present Sampled Layerwise Proofs (SLP), a protocol and prototype that commits the boundary activations of every chunk of an inference trace, absorbs all commitments before any challenge is drawn, and then proves a verifier-selected subset of chunks together with the chunks that bind the prompt and the answer. Audit coverage becomes a runtime parameter over one set of commitments: on a TinyLlama-1.1B trace, proving seven of 47 chunks takes 22.0% of the time and 6.8% of the proof size of proving all 47. Because proof cost is dominated by weights rather than tokens, SLP packs concurrent requests into one trace under a block-diagonal causal mask and binds the prompt and answer of each request to its slot. Twelve packed requests are proved in 181.9 s, 6.5 times less than twelve separate proofs at the measured single-proof cost, and a simulated service proves twelve requests at 30.6 s per request with 0.6 s of verification each, rejecting a tampered answer. Disk-backed integer weights and streamed polynomial commitments let a single Llama-2-70B run complete on a 2 TB CPU host: 163 chunks sealed, five proved, a 4.34 MiB proof in 1,259 s, verified in 46.3 s without the weights. The proven object is a fixed-point canonical model; we trace a severe fidelity loss to the residual-stream bit width, repair it with an LLM-aware observer, and measure 84.8-84.9% argmax agreement with the floating-point reference over 334,705 WikiText-2 test positions. The limits are stated as precisely: guarantees cover proven chunks only, a fixed invalid chunk in the 70B setting is covered with probability 3/161, a manifest-only Fiat-Shamir schedule can be ground at 12.5 ms per attempt and needs an externally ordered challenge, and all measurements use a test reference string.

Comments15 pages, 4 figures, 8 tables. Raw experiment logs and data tables: https://github.com/TrueOpen/slp-experiments

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑