What Does It Mean to Break a Distillation Defense?
Black-box LLMs (accessible only via API) are vulnerable to distillation attacks, in which an attacker queries the model and trains a student on its outputs. A recent line of work proposes output perturbation defenses that modify the teacher's output to reduce student performance while preserving utility for legitimate users. As a relatively new family of approaches, output perturbation defenses lack a shared threat model, making it difficult to compare them, reason about composing them with othe
Record details
Published: 23 June 2026
Source: arXiv
Category: Research
Topics: Military & security · Children & education
Retrieved: 14 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Toward Resilient Human-AI Collaboration: A Lifecycle Taxonomy of Sociotechnical Risks and Cascading Failures
arXiv cs.HC · 6 August 2026
A Conceptual Framework for Enhancing Workforce Readiness for Smart Manufacturing in the AI Era
arXiv cs.CY · 13 August 2026
GIGO and the Human Processor: A Chief Humanity Officer Review
OpenAlex · 18 March 2026
GIGO and the Human Processor: A CHO Review
OpenAlex · 18 March 2026
A Review on Virtual Reality Skill Training Applications
OpenAlex · 30 April 2021
Optimizing a machine learning based glioma grading system using multi-parametric MRI histogram and texture features
OpenAlex · 18 May 2017
How to cite this record
ethics.ai (23 June 2026), “What Does It Mean to Break a Distillation Defense?,” evidence record 636, https://ethics.ai/record/636 (originally published by arXiv).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.