Research
A Dishonest LLM Provider Can Inflate Your Output Tokens 10x, and One Probe Detects It
arXiv 2609.20370 (17 Sep 2026) defines the Provider-Side Token Inflation Attack and instantiates five variants at the query, prompt, representation and model levels of a provider-controlled pipeline, each raising mean output length above 10.2x the clean baseline while largely preserving task utility. The authors find PTIA saturates: the first attack sharply drops end-of-sequence token probability, further stacking barely moves it. That saturation becomes the audit, a single-probe test that applies a controlled lengthening intervention and needs no trusted local reference model and no historical clean responses.
↳ Follow the thread