Trace Inversion:无需思维链即可复制AI推理能力
You don’t necessarily need to see how a powerful AI thinks to copy some of its r…
You don’t necessarily need to see how a powerful AI thinks to copy some of its reasoning ability.
你不一定需要看到强大AI的思考过程,才能复制其部分推理能力。
Its final answers can contain enough signal to manufacture new reasoning traces for training another model.
其最终答案可能包含足够的信号,用于制造新的推理轨迹,以训练另一个模型。
The paper’s attack, Trace Inversion, only needs the model’s question, final answer, and optionally its short reasoning summary.
论文中的攻击方法“轨迹反转”仅需模型的提问、最终答案,以及可选的简短推理摘要。
A separate inversion model learns from an open reasoning model, then turns those sparse black-box outputs into long synthetic reasoning traces for training a student.
一个独立的反转模型从开源推理模型中学习,然后将这些稀疏的黑盒输出转化为长合成推理轨迹,用于训练学生模型。
The crucial point is that those traces do not have to match the victim’s true internal reasoning exactly.
关键在于,这些轨迹不必与受害者真实的内部推理完全一致。
They only have to be good enough supervision.
它们只需提供足够好的监督信号。
And the paper estimates $173.28 to collect 10,000 GPT-5.4 mini queries.
论文估计收集10,000个GPT-5.4 mini查询的成本为173.28美元。
So the defense problem now shifts: hiding or obfuscating chain of thought can reduce transparency without reliably preventing capability transfer.
因此,防御问题现在发生了转变:隐藏或混淆思维链可能会降低透明度,但无法可靠地阻止能力迁移。
The attacker can manufacture the missing training signal after the API call.
攻击者可以在API调用之后制造缺失的训练信号。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力