A model-stealing paper’s proof needs a stronger spanning assumption, the author says
ArthurConmy · x · 2026-08-04
This follow-up thread links the paper and the discussion chat, then clarifies that the author’s earlier claim had an error in the proof, though the main takeaway still stands.
The quoted paper is Stealing Part of a Production Language Model, which shows a black-box attack that can recover precise information from production LLM APIs, including embedding projection layers, hidden dimension sizes, and, for some models, the full projection matrix at low cost. The thread’s correction says the proof needs a stronger spanning assumption and notes related papers that move toward the right condition, but do not directly identify the flawed lemma.
More from Research
- Gemini Robotics ER 2 is being used to auto-annotate 69,000+ robot videos — DynamicWebPaige · 2026-08-04
- MerchantBench tests LLM agents over 365 days of simulated e-commerce operations — dair_ai · 2026-08-04
- 83 Sciences says unpublished and failed lab data helped it find a new material in 2 months — ycombinator · 2026-08-04
- Neural operators can flag tipping points early by tracking physics deviations — AnimaAnandkumar · 2026-08-04
- SALT stores chatbot memory in a trie and uses theme-based retrieval, but still over-retrieves — No_Sky9786 · 2026-08-04
- Why “interestingness” is too high-dimensional to learn from examples alone — dioscuri · 2026-08-04