arXiv:2606.29389cs.CRcs.LG2026-06

揭示Transformer实现加密技术的极限,为模型能力评估提供理论依据。

Exploring the Cryptographic Limits of Transformer Networks

论文配图:Exploring the Cryptographic Limits of Transformer Networks
图 1 · 摘自论文原文
  • 将三种加密结构映射为阈值电路,再转化为Transformer架构。
  • 推导出实现加密功能所需网络宽度与深度的可验证缩放规律。
  • 提出两种映射方法,适用于安全分析与模型能力评估。

近期研究显示,合谋的AI代理可利用隐写术交换恶意信息。Transformer能否实现隐写术,取决于其能否在层内实现密码学函数,因为具备该能力的Transformer可获得无源随机性。尽管已有电路复杂度结果,但此前缺乏将具体密码构造映射至Transformer架构的研究。鉴于Merrill等人指出饱和Transformer可视为阈值电路,本文首先为三种密码构造(Keccak函数、Merkle-Damgard构造、梅克尔树)生成阈值电路,并将其映射至不同Transformer架构。我们推导出每种密码构造实现所需的电路宽度与深度的已验证缩放规律,并提出两种映射方式:无注意力映射与令牌作为门控映射。除安全意义外,本工作建立了推导Transformer计算能力结构性保证的方法论,首次给出给定深度与宽度下变压器可能计算的构造性上界,为基于Transformer的AI系统能力评估提供了原则性基础。

原文摘要 · Abstract (English)

In recent work it has been shown that colluding AI agents can use steganographic methods to exchange malicious information. Whether a transformer can implement steganographic methods depends on what cryptographic functions it can implement, since a transformer that can implement a cryptographic function within its layers has source-free randomness access. Despite existing circuit-complexity results, no prior work maps specific cryptographic constructions to transformer architectures. As Merrill et al. have shown that saturated transformers can be seen as threshold circuits, we first generate threshold circuits for three different cryptographic constructions (Keccak functions, Merkle--Damgard constructions and Merkle Trees) and then map these circuits to different transformer architectures. We derive verified scaling laws for the width and depth of the circuits which implement each cryptographic construction and propose two different mappings: no-attention mapping, tokens-as-gates mapping. Beyond its security implications, this work contributes to by establishing a methodology for deriving structural guarantees on transformer computational capacity. Specifically, we derive constructive upper bounds on what a transformer of a given depth and width could plausibly compute, providing a principled foundation for capability evaluations of transformer-based AI systems.

密码学Transformer隐写术计算能力

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。