---
格式版本: 2
标题: "Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs"
原文链接: "https://arxiv.org/abs/2608.16391"
发布日期: "2026-08-17"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:scrape:strict_html_body"
发布时间证据: "citation_date: 2026/08/17"
发布时间校准原因: "规则确认唯一严格发布时间，来源 scrape:strict_html_body"
发布时间校准置信度: "high"
发布时间候选数量: 6
发布时间严格候选数量: 6
发布时间原页读取状态: ""
发布时间未找到原因: ""
发布时间校准时间: "2026-08-18T19:35:37+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-18T19:35:26+08:00"
入库时间: "2026-08-18T11:35:49.652Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 0
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为LLM API安全审计，与超节点/AI Rack/机柜级AI基础设施完全无关，仅命中泛化关键词AI。"
AI质检模型: "tx-deepseek-v4-flash"
AI质检时间: "2026-08-18T19:36:55+08:00"
AI主题相关性: 0
AI来源权威性: 0
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "Ventor-QTest 提出一种针对第三方托管 LLM API 的黑盒审计方法，通过重复请求与长序列探测计算平均保真度损失（AFL）和极端保真度损失（EFL），无需目标 API 提供概率信息。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:24:36.514Z"
采集批次: "2026年8月18日15点52分05秒"
采集批次ID: "20260818-155205-090"
去重键: "https://arxiv.org/abs/2608.16391"
---

## Computer Science > Cryptography and Security

## Title:Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs

Authors:[Xiangfan Wu](https://arxiv.org/search/cs?searchtype=author&query=Wu,+X), [Zonghao Ying](https://arxiv.org/search/cs?searchtype=author&query=Ying,+Z), [Huiyu Wu](https://arxiv.org/search/cs?searchtype=author&query=Wu,+H), [Xing Zheng](https://arxiv.org/search/cs?searchtype=author&query=Zheng,+X), [Huangsheng Cheng](https://arxiv.org/search/cs?searchtype=author&query=Cheng,+H), [Xiaorong Shi](https://arxiv.org/search/cs?searchtype=author&query=Shi,+X), [Jing Guo](https://arxiv.org/search/cs?searchtype=author&query=Guo,+J)

[View PDF](https://arxiv.org/pdf/2608.16391) [HTML (experimental)](https://arxiv.org/html/2608.16391v1)

> Abstract:As large language models become increasingly widespread, third-party providers that deploy open-weight models have become an important part of the ecosystem. Auditing the quality of their inference APIs is therefore an open problem. We formalize hosted model routing as a stochastic process and propose \\mbox{\\textbf{Ventor-QTest}}, a composite black-box audit that requires no probability information from the target API. Its repeated-request component sends each frozen constrained context to the target multiple times, reconstructs a categorical output distribution from the returned text counts, and reports \\emph{average fidelity loss} (AFL) as a null-bias-corrected, within-window mean coarsened-KL statistic. Its long-sequence component uses independent runs to report \\emph{extreme fidelity loss} (EFL) through the empirical upper tail of a run-level reference-centered-surprisal statistic. Across three logprob-capable route conditions, AFL shows strong linear descriptive agreement with a logprob-derived coarsened-KL comparator. Across seven route snapshots, 20-run sequence probes reveal route-specific EFL variation. AFL and EFL have little detectable route-level association with GPQA-Diamond accuracy. In contrast, pronounced EFL coincides with a decline in Terminal-Bench pass rate as task exposure increases. This pattern may arise because correctness in long-horizon tasks is more sensitive to extreme fidelity loss. These results motivate reporting AFL and EFL jointly, particularly when auditing long-horizon agentic tasks. The open-source implementation is available at [this https URL](https://github.com/Tencent/AI-Infra-Guard/tree/main/services/api_checker/ventor_qtest).

| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) |
| --- | --- |
| Cite as: | [arXiv:2608.16391](https://arxiv.org/abs/2608.16391) \[cs.CR\] |
|  | (or [arXiv:2608.16391v1](https://arxiv.org/abs/2608.16391v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.16391](https://doi.org/10.48550/arXiv.2608.16391) |

## Submission history

From: Xiangfan Wu \[[view email](https://arxiv.org/show-email/91496bd1/2608.16391)\]  
**\[v1\]** Mon, 17 Aug 2026 10:41:18 UTC (155 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.16391) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
