Spotlight talk at the MATS 10 Research Symposium, selected as one of ten spotlight presentations out of roughly 70 fellow projects across the Agency, Evaluations, Governance & Strategy, Oversight & Control, and Security research tracks.

Joint work with Matt Kowalczyk, mentored by Keri Warr (Anthropic). A compromised LLM inference server can leak model weights by encoding payload bits in otherwise plausible token choices. The talk presents inference verification mechanisms that bound the capacity of this covert channel and detect such steganographic exfiltration in the token stream.

Talk recording · Slides · Symposium gallery and recordings