AIHOT 于 2026-08-17 收录了“Ventor-QTest:面向第三方托管大模型 API 的威胁模型驱动审计”这一公开动态。以下先呈现从来源页面抓取的正文,再给出 AIHOT 摘要与 TopoReduce 编辑解读。
PUBLIC SOURCE CONTENT
已抓取公开正文公开原文内容
[2608.16391] Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs
Computer Science > Cryptography and Security
arXiv:2608.16391 (cs)
-
[Submitted on 17 Aug 2026]
Title:Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs
Authors:Xiangfan Wu, Zonghao Ying, Huiyu Wu, Xing Zheng, Huangsheng Cheng, Xiaorong Shi, Jing Guo
View a PDF of the paper titled Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs, by Xiangfan Wu and 6 other authors
View PDF
HTML (experimental)
Abstract:As large language models become increasingly widespread, third-party providers that deploy open-weight models have become an important part of the ecosystem. Auditing the quality of their inference APIs is therefore an open problem. We formalize hosted model routing as a stochastic process and propose \mbox{\textbf{Ventor-QTest}}, a composite black-box audit that requires no probability information from the target API. Its repeated-request component sends each frozen constrained context to the target multiple times, reconstructs a categorical output distribution from the returned text counts, and reports \emph{average fidelity loss} (AFL) as a null-bias-corrected, within-window mean coarsened-KL statistic. Its long-sequence component uses independent runs to report \emph{extreme fidelity loss} (EFL) through the empirical upper tail of a run-level reference-centered-surprisal statistic. Across three logprob-capable route conditions, AFL shows strong linear descriptive agreement with a logprob-derived coarsened-KL comparator. Across seven route snapshots, 20-run sequence probes reveal route-specific EFL variation. AFL and EFL have little detectable route-level association with GPQA-Diamond accuracy. In contrast, pronounced EFL coincides with a decline in Terminal-Bench pass rate as task exposure increases. This pattern may arise because correctness in long-horizon tasks is more sensitive to extreme fidelity loss. These results motivate reporting AFL and EFL jointly, particularly when auditing long-horizon agentic tasks. The open-source implementation is available at this https URL.
Subjects:
Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as:
arXiv:2608.16391 [cs.CR]
(or
arXiv:2608.16391v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.16391
Focus to learn more
arXiv-issued DOI via DataCite (pending registration)
Submission history
From: Xiangfan Wu [view email]
[v1]
Mon, 17 Aug 2026 10:41:18 UTC (155 KB)
Full-text links:
Access Paper:
View a PDF of the paper titled Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs, by Xiangfan Wu and 6 other authors
- View PDF
- HTML (experimental)
- TeX Source
view license
Current browse context:
cs.CR
< prev
|
next >
new
|
recent
| 2026-08
Change to browse by:
cs
cs.AI
References & Citations
- NASA ADS
- Google Scholar
- Semantic Scholar
export BibTeX citation
Loading...
BibTeX formatted citation
×
loading...
Data provided by:
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Code, Data and Media Associated with this Article
alphaXiv Toggle
alphaXiv (What is alphaXiv?)
Links to Code Toggle
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub Toggle
DagsHub (What is DagsHub?)
GotitPub Toggle
Gotit.pub (What is GotitPub?)
Huggingface Toggle
Hugging Face (What is Huggingface?)
ScienceCast Toggle
ScienceCast (What is ScienceCast?)
Demos
Demos
Replicate Toggle
Replicate (What is Replicate?)
Spaces Toggle
Hugging Face Spaces (What is Spaces?)
Spaces Toggle
TXYZ.AI (What is TXYZ.AI?)
Related Papers
Recommenders and Search Tools
Link to Influence Flower
Influence Flower (What are Influence Flowers?)
Core recommender toggle
CORE Recommender (What is CORE?)
- Author
- Venue
- Institution
- Topic
About arXivLabs
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.
Which authors of this paper are endorsers? |
Disable MathJax (What is MathJax?)
arXiv:2608.16391 (cs)
-
[Submitted on 17 Aug 2026]
Title:Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs
Authors:Xiangfan Wu, Zonghao Ying, Huiyu Wu, Xing Zheng, Huangsheng Cheng, Xiaorong Shi, Jing Guo
View a PDF of the paper titled Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs, by Xiangfan Wu and 6 other authors
View PDF
HTML (experimental)
Abstract:As large language models become increasingly widespread, third-party providers that deploy open-weight models have become an important part of the ecosystem. Auditing the quality of their inference APIs is therefore an open problem. We formalize hosted model routing as a stochastic process and propose \mbox{\textbf{Ventor-QTest}}, a composite black-box audit that requires no probability information from the target API. Its repeated-request component sends each frozen constrained context to the target multiple times, reconstructs a categorical output distribution from the returned text counts, and reports \emph{average fidelity loss} (AFL) as a null-bias-corrected, within-window mean coarsened-KL statistic. Its long-sequence component uses independent runs to report \emph{extreme fidelity loss} (EFL) through the empirical upper tail of a run-level reference-centered-surprisal statistic. Across three logprob-capable route conditions, AFL shows strong linear descriptive agreement with a logprob-derived coarsened-KL comparator. Across seven route snapshots, 20-run sequence probes reveal route-specific EFL variation. AFL and EFL have little detectable route-level association with GPQA-Diamond accuracy. In contrast, pronounced EFL coincides with a decline in Terminal-Bench pass rate as task exposure increases. This pattern may arise because correctness in long-horizon tasks is more sensitive to extreme fidelity loss. These results motivate reporting AFL and EFL jointly, particularly when auditing long-horizon agentic tasks. The open-source implementation is available at this https URL.
Subjects:
Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as:
arXiv:2608.16391 [cs.CR]
(or
arXiv:2608.16391v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.16391
Focus to learn more
arXiv-issued DOI via DataCite (pending registration)
Submission history
From: Xiangfan Wu [view email]
[v1]
Mon, 17 Aug 2026 10:41:18 UTC (155 KB)
Full-text links:
Access Paper:
View a PDF of the paper titled Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs, by Xiangfan Wu and 6 other authors
- View PDF
- HTML (experimental)
- TeX Source
view license
Current browse context:
cs.CR
< prev
|
next >
new
|
recent
| 2026-08
Change to browse by:
cs
cs.AI
References & Citations
- NASA ADS
- Google Scholar
- Semantic Scholar
export BibTeX citation
Loading...
BibTeX formatted citation
×
loading...
Data provided by:
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Code, Data and Media Associated with this Article
alphaXiv Toggle
alphaXiv (What is alphaXiv?)
Links to Code Toggle
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub Toggle
DagsHub (What is DagsHub?)
GotitPub Toggle
Gotit.pub (What is GotitPub?)
Huggingface Toggle
Hugging Face (What is Huggingface?)
ScienceCast Toggle
ScienceCast (What is ScienceCast?)
Demos
Demos
Replicate Toggle
Replicate (What is Replicate?)
Spaces Toggle
Hugging Face Spaces (What is Spaces?)
Spaces Toggle
TXYZ.AI (What is TXYZ.AI?)
Related Papers
Recommenders and Search Tools
Link to Influence Flower
Influence Flower (What are Influence Flowers?)
Core recommender toggle
CORE Recommender (What is CORE?)
- Author
- Venue
- Institution
- Topic
About arXivLabs
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.
Which authors of this paper are endorsers? |
Disable MathJax (What is MathJax?)
AIHOT 摘要
Ventor-QTest 提出一种无需目标 API 概率信息的复合黑盒审计方法,通过重复请求与长序列组件分别报告平均保真度损失(AFL)和极端保真度损失(EFL)。在七组路由快照中,EFL 随任务暴露增加与 Terminal-Bench 通过率下降同步出现,提示审计长程智能体任务时应联合报告 AFL 与 EFL。实现已开源。
为什么值得关注
这套审计把重复请求变成可计算的输出分布差异,部署第三方托管模型时的供应商质量检查多了一个不依赖 logprob 的量化指标。
工程化解读
从 TopoReduce 的工程视角看,这条信息属于“论文与研究”主题。它的价值不只在于一个新产品或新观点本身,还在于说明 AI 系统正在如何影响模型接入、智能体协作、研发流程、基础设施和团队决策。实际采用前,应结合原文确认版本、适用范围、价格和运行条件。
- 发布时间:2026-08-17;AIHOT 分类:论文与研究。
- AIHOT 标签:
- AIHOT 判断:这套审计把重复请求变成可计算的输出分布差异,部署第三方托管模型时的供应商质量检查多了一个不依赖 logprob 的量化指标。
- AIHOT 评分:54;评分用于站内排序,不等同于独立评测结论。
TopoReduce 编辑观察
当 AI 动态进入真实生产环境,团队需要同时关注能力边界、数据来源、调用成本、权限控制和可回滚性。把单条新闻放回完整工程链路中阅读,比只看标题更有助于判断它是否适合自己的产品和工作流。