Top
Best
New

Posted by quantumgarbage 22 hours ago

Stealing Reasoning Traces from Proprietary LLM APIs(stolen-thoughts.com)
630 points | 284 commentspage 3
ziofill 20 hours ago|
I understand it’s cool to have an artistic website, but it’s very noisy and non-accessible.

But very interesting result.

benob 19 hours ago||
A natural next step is to use the reasoning traces to jailbreak the stronger models (https://arxiv.org/pdf/2603.12277)
certainforest 16 hours ago|
+1
sm-silversight 16 hours ago||
Is this basically a paper on how to distill, in exactly the fashion openai/anthropic don't want/say is copyright theft?
pradeep1177 16 hours ago||
These logs containing opaque blobs could accidentally contain secrets, the researchers decoded many of reasoning blocks from public repositories and reported finding PII and credentials.

I was experimenting a bit how I could block these using an ingress path. GitHub /softcane/hamza

blmarket 12 hours ago||
I expect future LLM will refuse to share the reason. "Hey, how did you come up with this idea?" "you have to pay enterprise API to learn this"
Cynddl 19 hours ago||
> The providers did not acknowledge “any security implications arising from side channels or replay attacks.” All model providers acknowledged the receipt of our report and subsequently we were unable to launch the same attacks.

I went straight to the ‘Responsible Disclosure’ section. Not surprising, but still disappointing.

arjie 17 hours ago||
Wow, almost certainly the approach that alternative labs use to distill Claude. I always wondered how far they could get with just the answer missing the reasoning. They probably actually also had the reasoning.
fractorial 20 hours ago||
Fascinating approach; however, a nightmare to scroll on mobile.
C0ldSmi1e 17 hours ago||
Why they use different models to decode the reasoning content? Can the the model decode it?
aszen 17 hours ago|
Because stronger models are harder to jailbreak from the paper it says haiku was easily fooled into giving us thinking contents
hahahaa 12 hours ago|
You wouldn't steal ... the token output you paid for.
More comments...