发表机构
Carnegie Mellon University; Max Planck Institute for Software Systems(卡内基梅隆大学; 马克斯·普朗克软件系统研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对大模型推理收费中提供商可能人为增加路径数的问题,提出策略性自一致性算法,通过生成并重排额外路径规避审计,实验显示在Llama、Qwen及DeepSeek-R1蒸馏模型上存在显著超额收费空间。
AI 中文摘要
自一致性已成为一种流行的技术,通过生成多条推理路径并采用多数投票选择最终答案来增强大型语言模型的推理能力。然而,由于模型提供商通常按生成的推理路径数量向用户收费,他们存在人为增加路径数量的经济动机。在这项工作中,我们证明了一个不诚实的提供商可以利用这一动机,使用一种简单高效的算法,同时避免被审计者发现:通过生成并策略性地重新排序额外的推理路径,该算法使每条路径看起来都是达成多数所必需的。为了验证我们的算法,我们使用来自Llama和Qwen家族的多个指令模型,以及从DeepSeek-R1蒸馏的推理模型,在涵盖数学、科学和问答的基准数据集上进行了实验。我们的结果表明,我们的算法生成的额外推理路径的分布呈重尾分布,并且即使在旨在将假阳性率控制在α=0.1以下的最佳可能审计下,仍存在大量的超额收费能力。
英文摘要
Self-consistency has become a popular technique for enhancing the reasoning abilities of large language models by generating multiple reasoning paths and selecting the final answer through a majority vote. However, because model providers typically charge users in proportion to the number of reasoning paths generated, they have a financial incentive to artificially increase the path count. In this work, we show that an unfaithful provider can exploit this incentive using a simple, efficient algorithm while avoiding detection by an auditor: by generating and strategically reordering additional reasoning paths, the algorithm makes every path appear necessary to reach the majority. To validate our algorithm, we conduct experiments with multiple instruct models from the Llama and Qwen families, as well as reasoning models distilled from DeepSeek-R1, on benchmark datasets spanning mathematics, science, and question answering. Our results suggest that the distribution of additional reasoning paths generated by our algorithm is heavy-tailed and that substantial capacity to overcharge remains even under the best possible audit designed to keep the false-positive rate below $α= 0.1$.