{
  "id": 636,
  "url": "https://arxiv.org/abs/2606.25059v2",
  "title": "What Does It Mean to Break a Distillation Defense?",
  "summary": "Black-box LLMs (accessible only via API) are vulnerable to distillation attacks, in which an attacker queries the model and trains a student on its outputs. A recent line of work proposes output perturbation defenses that modify the teacher's output to reduce student performance while preserving utility for legitimate users. As a relatively new family of approaches, output perturbation defenses lack a shared threat model, making it difficult to compare them, reason about composing them with othe",
  "authors": "Lena Libon, Pura Peetathawatchai, Michael Aerni, Daniel Paleka, Florian Tramèr",
  "category": "research",
  "topics": "military-security,children-education",
  "orgs": null,
  "regions": null,
  "published_at": "2026-06-23T18:13:02.000Z",
  "fetched_at": "2026-07-14T14:14:41.550Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/636",
  "original_url": "https://arxiv.org/abs/2606.25059v2",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}