This paper studies output integrity in peer-to-peer distributed LLM inference, where model layers are hosted by independently controlled consumer devices. It proposes mixing secret canary inputs into ordinary traffic and comparing each shard’s activations with known reference activations. Benign hardware variation should produce small deviations, while tampering should create substantially larger drift. Malicious-node identification is framed as a probabilistic test separating two drift distributions rather than applying a fixed threshold. Across 408 configurations with metrics and success criteria fixed before experimentation, the detector achieved AUROC 1.0 and ranked the malicious shard above every benign shard for every canary in every configuration.
No heat snapshots are available in the last 24 hours.