LATIDIA · Ciberseguridad
Cuanto más dice, más paga: una auditoría de caja negra de la inflación de tokens del lado del proveedor en los servicios de LLM
arXiv: 2609.20370v1Tipo de anuncio: nuevo Resumen: En los servicios LLM de pago por token, cuanto más dice un modelo, más pagan los usuarios. Los proveedores deshonestos pueden manipular encubiertamente la generación para inflar los tokens de salida mientras pres
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.20370v1 Announce Type: new Abstract: In pay-per-token LLM services, the more a model says, the more users pay. Dishonest providers can covertly manipulate generation to inflate output tokens while largely preserving task utility. We define such manipulation as a Provider-Side Token Inflation Attack (PTIA) and instantiate five representative attacks at the query, prompt, representation, and model levels of the provider-controlled pipeline. Our experiments show that each attack increases mean output length to more than 10.2x the clean baseline, demonstrating PTIA's financial appeal and feasibility at multiple stages of generation. Yet auditing PTIA from black-box responses is difficult for users. Our key observation is PTIA saturation: an initial attack sharply lengthens