Skip to content

perf(bpe): pack a short word into its key instead of hashing it - #2315

Merged
ArthurZucker merged 1 commit into
perf/bpe-hash-word-oncefrom
perf/bpe-pack-short-keys
Aug 7, 2026
Merged

perf(bpe): pack a short word into its key instead of hashing it#2315
ArthurZucker merged 1 commit into
perf/bpe-hash-word-oncefrom
perf/bpe-pack-short-keys

Conversation

@ArthurZucker

Copy link
Copy Markdown
Collaborator

Stacked on #2313 — review that first; this PR's diff is only the second commit.

What

A pretoken is short: english averages 4.83 bytes, code 4.08, and the <|...|> shapes in
added-special-dense 2.29. Running aHash over that is most of what the fold probe costs, and it
buys nothing — the vocabulary compares the entry's bytes regardless, so the hash only has to spread
well enough for the MPHF to separate keys.

For a word of ≤7 bytes, pack the bytes and the length into a u64 and mix them with one
multiply. Seven, so the length still fits in the top byte — that is what stops "ab" colliding with
"ab\0". Longer words keep aHash, which mixes the length in itself.

One definition, not two

word_hash is now the single place a word becomes a u64. BucketVocabStore::build, every probe,
and the word cache's placement all route through it, so a pretoken probed in both tables is hashed
once for the pair and the two cannot drift apart. The per-struct RandomState field goes away with
it: consistency used to come from carrying the hasher on the struct, and now it comes from there
being one function.

The debug_assert #2313 added earned its keep immediately — it caught WordCache::lookup still
calling a hasher of its own while lookup_hashed expected word_hash, which would have left the
cache placing short words under one value and looking them up under another (no wrong ids, but a
permanent 0% hit rate).

Exactness is unchanged

Nothing verifies with mix. The vocabulary still compares the entry's bytes to the query in full;
the cache still compares its 128-bit key. So this cannot change any id, and it does not carry the
2^-32 digest weakening discussed on #2313.

Dropping the mixing entirely does not work, incidentally: packed short keys share their high bytes
and MPHF construction fails outright with indistinguishable hashes in bucket.

Why this path was chosen

Measured on tokbench (gpt2, 29 cells, --reps 1, all byte-exact), splitting the suite by ASCII byte
fraction separates it cleanly:

group n mean ratio vs gigatoken mean excess per pretoken
>97% ASCII 14 0.766x — all 14 are losses +3.01 ns (median +2.93)
non-ASCII 15 1.203x −13.46 ns

A near-constant ~3 ns ≈ 10 cycles per ASCII pretoken, and the sign flips on non-ASCII where words
exceed the inline key and both sides hash for real. The one ASCII cell at parity is dense (+0.07),
which has 24.3 bytes per pretoken so a per-pretoken constant amortises away. aHash over a short word
is ~8–12 cycles against a masked load plus a multiply at ~2–3, which lands on that measurement.

Ruled out first, all measured: merges (added-special-dense does the least merge work of any cell —
1.17 get_value/pretoken vs english's 1.94 — and is the worst cell at 0.485x), the GATE_ASCII
crossover (sweep is monotonically worse below 20), the added-token matcher (0.05–0.11 ns/B at real
candidate densities, <10% of the excess anywhere), and per-call overhead (ScratchPool's mutex plus
the output allocation is ~0.12 ns/pretoken, ~4% of the gap).

Verification

cargo test -p tk-encode --all-features: 357 passed. the_proven_fold_never_changes_the_ids
passes, which is the id-for-id gate against the legacy reference over folded words, merged words,
<|endoftext|>, CJK and code.

One unrelated failure, normalizers::precompiled::tests::pipeline_precompiled_matches_legacy, is
present on a clean checkout of the base too and is a missing fixture. fold_tests need
tokenizers/data/gpt2.json; make data fetches it.

No throughput number is claimed here — the per-cell noise floor on this machine is 8–13% on exactly
the ASCII cells this targets (identical code, three runs: english 8.5% spread, math-latex 12.8%),
so a ~3 ns/pretoken effect is below what it can resolve. The argument is the instruction count.

Follow-up this sets up

The fold probe is 3 dependent loads (MPHF pilot → entry → byte-slab memcmp) where the cache's is 2,
purely because the cache keeps its key in the slot. Now that a short token's key is its bytes
plus length, storing that key in Entry makes verification an exact u64 compare and drops the fold
probe to 2 loads with no loss of exactness — only tokens over 7 bytes would still need the slab.
Separate change, separate review, since it alters Entry's layout.

Note on the base

#2313 is based on the tip before #2304 merged, and feat/train_encode_split does not currently build
(see #2314). This stack wants a rebase once that lands; the #[allow(dead_code)] on fold_id is an
artefact of that stale base — the batched tokenize_spans is its caller.

A pretoken is short. English averages 4.83 bytes of it, code 4.08, and the `<|...|>`
shapes in `added-special-dense` 2.29. Running aHash over that is most of what the
fold probe costs, and it buys nothing: the vocabulary compares the entry's bytes
anyway, so the hash only has to spread well enough for the MPHF to separate keys.

For a word of seven bytes or fewer, pack the bytes and the length into a `u64` and mix
them with one multiply. Seven, so the length still fits in the top byte, which is what
keeps `"ab"` from colliding with `"ab\0"`. Longer words keep aHash, which mixes the
length in itself.

`word_hash` is now the one definition. `BucketVocabStore::build`, every probe, and the
word cache's placement all go through it, so a pretoken probed in both tables is
hashed once for the pair and the two cannot drift apart. The per-struct `RandomState`
goes away with it: consistency came from carrying the hasher around, and now it comes
from there being a single function.

Verification is unchanged and stays exact -- the vocabulary still compares the entry's
bytes to the query in full, the cache still compares its 128-bit key. Nothing verifies
with `mix`, which is why it does not have to be a strong hash. Dropping the mixing
altogether does not work: packed short keys share their high bytes and MPHF
construction fails with "indistinguishable hashes in bucket".

Note this is why `WordCache::lookup` has to call `placement_hash_of` rather than a
hasher of its own: the `debug_assert` in `lookup_hashed` caught exactly that mistake
while this was being written.
@HuggingFaceDocBuilderDev

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@ArthurZucker

Copy link
Copy Markdown
Collaborator Author

Rebased onto feat/train_encode_split now that #2314 has landed (rebase is local until the branch is force-pushed).

Benched the whole stack: geomean 1.1493x over 29 gpt2 cells, 29/29 faster, all ids identical, interleaved A/B/A/B/A/B. Full numbers and method on #2316.

Note the stack has to land together to show that. pipeline.rs routes encode through tokenize_spans, and these PRs only wired tokenize_pipeline — so on its own this PR touches a path the encode loop does not use. The final commit of the stack wires the batched path.

@ArthurZucker
ArthurZucker merged commit 473db76 into perf/bpe-hash-word-once Aug 7, 2026
36 of 42 checks passed
@ArthurZucker
ArthurZucker deleted the perf/bpe-pack-short-keys branch August 7, 2026 04:17
ArthurZucker added a commit that referenced this pull request Aug 7, 2026
* perf(bpe): hash a word once for both the fold and the cache probe

`tokenize_pipeline` hashed every fold-missing pretoken twice: `fold_id` hashed it
for the vocabulary's MPHF, then `WordCache::lookup` hashed the same bytes again
for its home slot and tag. `BucketVocabStore` and `WordCache` seed `ahash` with
the same four constants, so the second pass recomputed a value the first had
already produced.

Share it: `hash_word` exposes the value, `get_bytes_foldable_hashed` and
`lookup_hashed` take it, and the model computes it once per word.

Verification is untouched. The vocabulary still compares the entry's bytes to
the query in full, and the cache still compares its key, so ids cannot change --
only the duplicated hash goes away. A word over fifteen bytes still pays the
cache's second, independently seeded discriminant hash, which is what makes its
key 127 bits rather than 64.

The sharing is only sound while both sides seed identically, so a test pins them
together. Re-seeding either would leave the cache placing a word under one hash
and looking it up under another: no wrong ids, but every lookup would miss and
the cache would quietly stop working.

* fix(bpe): repair `tokenize_spans`, which does not compile (#2314)

#2304 added `PipelineBPE::tokenize_spans` against the model as it stood then. #2241
replaced the merge engines and #2310 dropped `ignore_merges`, and because the two
landed on separate branches the merge produced a `feat/train_encode_split` that does
not build:

  error[E0425]: cannot find type `Span` in this scope
  error[E0026]: struct `BpeScratch` does not have fields named `merge_queue`, `skip`, `word`
  error[E0027]: pattern does not mention fields `symbols`, `queue`
  error[E0609]: no field `ignore_merges` on type `&PipelineBPE`
  error[E0061]: this method takes 3 arguments but 4 arguments were supplied

Bring the batch loop back in line with `tokenize_pipeline`: destructure
`{ symbols, queue, word_cache }`, run the fold, and call the current
`merge_word(sequence, symbols, queue)` followed by `unmap`.

The fold has to stay ahead of the cache probe, as it is in `tokenize_pipeline`. A word
that is a foldable vocabulary entry is answered in one probe and never enters the
cache; probing the cache first would fill it with words the fold already serves for
free, and the two paths would disagree about its contents.

`tokenize_spans` overrides a trait method whose default is the `tokenize_pipeline`
loop, so the two can drift without anything failing to build -- that is how this got
in. Add a test that runs thousands of spans through one chunk (repeats, so the cache
fills and hits; folded words; merged words; punctuation runs; multi-byte scripts; a
long unbroken run) and compares the ids to the legacy reference.

* perf(bpe): pack a short word into its key instead of hashing it (#2315)

A pretoken is short. English averages 4.83 bytes of it, code 4.08, and the `<|...|>`
shapes in `added-special-dense` 2.29. Running aHash over that is most of what the
fold probe costs, and it buys nothing: the vocabulary compares the entry's bytes
anyway, so the hash only has to spread well enough for the MPHF to separate keys.

For a word of seven bytes or fewer, pack the bytes and the length into a `u64` and mix
them with one multiply. Seven, so the length still fits in the top byte, which is what
keeps `"ab"` from colliding with `"ab\0"`. Longer words keep aHash, which mixes the
length in itself.

`word_hash` is now the one definition. `BucketVocabStore::build`, every probe, and the
word cache's placement all go through it, so a pretoken probed in both tables is
hashed once for the pair and the two cannot drift apart. The per-struct `RandomState`
goes away with it: consistency came from carrying the hasher around, and now it comes
from there being a single function.

Verification is unchanged and stays exact -- the vocabulary still compares the entry's
bytes to the query in full, the cache still compares its 128-bit key. Nothing verifies
with `mix`, which is why it does not have to be a strong hash. Dropping the mixing
altogether does not work: packed short keys share their high bytes and MPHF
construction fails with "indistinguishable hashes in bucket".

Note this is why `WordCache::lookup` has to call `placement_hash_of` rather than a
hasher of its own: the `debug_assert` in `lookup_hashed` caught exactly that mistake
while this was being written.

* perf(bpe): put the key in the entry, so the fold probe is two loads (#2316)

The fold probe was three dependent loads: the MPHF pilot, the entry, then the byte slab
to compare the token against the query. The word cache does the same job in two, and the
reason is layout, not luck -- its key lives in the slot it verifies, so nothing else has
to be read.

Give the vocabulary the same shape. `Entry` becomes `{ key, id }`, and `(start, len)`
moves to a parallel `spans` array that only the reverse lookup and enumeration touch.
A probe is now pilot + entry.

Verification stays exact. A word of `INLINE_KEY_BYTES` or fewer has a key that *is* its
bytes and its length, so comparing keys is proof of identity and the slab is never read.
A longer word keys by aHash, which is not proof, so it still confirms against the slab --
the load it was paying anyway. So the saving lands exactly on the short pretokens that
are the gap (english averages 4.83 bytes, code 4.08, `added-special-dense` 2.29) and
nothing gives up the never-wrong guarantee.

`LEN_TAG` now biases the length by one. A non-minimal MPHF returns padding slots, whose
`Entry::default()` key is 0, and the probe rejects those with the same single compare it
uses for everything else -- which only works while no real word can key to 0. The empty
word keyed to exactly that before the bias.

`key_and_hash` returns both halves so neither is recomputed: the model runs it once per
word and hands the key and the hash to the fold probe and the hash to the cache.

* perf(bpe): hash once on the batched path too

`pipeline.rs` encodes through `tokenize_spans`, not `tokenize_pipeline`, and
`tokenize_spans` was still hashing each word twice: `fold_id` for the vocabulary,
then `cache.lookup` for the cache. Everything this PR does was landing only on
`tokenize_pipeline`, which the encode loop does not call.

Run `key_and_hash` once per word and hand the pair to `fold_id_keyed` and the hash
to `lookup_hashed`, as `tokenize_pipeline` already does. `fold_id` had exactly one
caller and folded into `fold_id_keyed` with it, taking a stale `#[allow(dead_code)]`
with it.

`the_batched_path_matches_the_reference` covers the path: ids compared against the
legacy reference over thousands of spans in one chunk.

* perf(pipeline): let the caller own the output buffer

`encode_generic` sizes a fresh `Vec` from the input length -- a guess -- and hands back
a new allocation on every call. A caller encoding many inputs (a batch, a server loop, a
benchmark) can reserve once and `clear()` between calls instead: fewer allocations, and
no first-touch of the token array each time.

Split it: `encode_generic_into` takes `&mut Vec<PipelineToken>`, and `encode_generic`
becomes the allocating wrapper, so nothing existing changes.

Measured on identical code with both forms available, tokbench gpt2, 29 cells against
gigatoken: 0.9233x allocating vs 0.9536x reusing -- ~3% of geomean throughput, ~6% on
english (3.188 -> 3.001 ns/B).

* merge: resolve duplicate tokenize_spans (keep the cache-aware, keyed version)

The merge of #2313 into #2306 left two `tokenize_spans` definitions: git took both
sides textually because they landed in different places. The stale one is #2306's,
predating the word cache -- it destructures `BpeScratch { symbols, queue }` with no
`word_cache` and calls the removed `fold_id`. Dropped it; kept the version that
folds, probes the cache, and hashes each word once.

* perf(bpe): carry pair ranks across multipass passes, and stop splicing

Two changes to the multipass engine, ported from the target-encode work.

**Ranks carried across passes.** A pass used to re-look-up every pair it walked over, so the
passes summed to O(n^2) table lookups -- measured at **41.9 per merged word**. Only the pairs
touching a merge's product actually change, so `ranks[i]` (the value of the pair
`(symbols[i], symbols[i+1])`) is now seeded by `convert_multipass` -- which already looks every
pair up, so seeding costs one store per pair and no extra lookup -- and carried. A pass copies
the ranks it did not invalidate and pays `get_value` **twice per merge** instead of once per
symbol. Finding the next target is then a scan of `ranks` with no lookups at all. `prods` holds
the matching product ids, kept apart so the search array stays a dense `u32` of ranks alone.

**No memmove per merge.** A merge used to splice: write the product, then `copy_within` symbols,
ranks and products to close the gap -- three memmoves on every merge. Instead the word carries a
`live` bitmap of which slots still hold a symbol and a merge clears one bit; "previous live" and
"next live" are `leading_zeros`/`trailing_zeros`. The `MAX_MP = 24` bound is what makes this work:
it puts the live set in one `u64`. Dead pair slots hold `u32::MAX`, which is also "does not merge",
so the minimum search skips them for free.

The superseded sweep machinery (`MergeState`, `merge_once`, `batch_merging_is_safe`, `NOT_LEGAL`)
goes with it -- the batching those implemented is subsumed by carrying ranks.

Byte-exact: `the_proven_fold_never_changes_the_ids` and `the_batched_path_matches_the_reference`
both compare ids against the legacy reference.

* perf(bpe): write cache hits straight at the output cursor

A cache hit went through the tag row -- one load of 16 control bytes, a SIMD compare, then
the slot -- and handed back a slice the caller walked. Both are avoidable for the common
case, a word cached in its own home slot with at most three ids.

`probe_emit_hashed` reads the home slot directly and stores all `MAX_INLINE_IDS` lanes
unconditionally at a `*mut u32` the caller supplies, so the line is touched once and the ids
never become a slice. Lanes past `ids_len` are dead: the caller advances its cursor by
`ids_len` only, so the next word overwrites them or the final `set_len` cuts them off. A
spilled or off-home slot falls back to the window walk without re-keying the word
(`lookup_placed`, split out of `lookup_hashed`).

`tokenize_spans` keeps a raw cursor and one capacity check per word covering both the fold's
single write and the probe's lanes, and reserves `2 * spans.len() + MAX_INLINE_IDS` up front
-- 92% of english pre-tokens are one id and 98% at most two, so the old `spans.len()` was a
lower bound that made the buffer grow, and memcpy what it held, partway through most chunks.

Deliberately NOT taken from the source branch: its `LookupKey` is a `u64`, which makes a hit
on a word over seven bytes a 2^-64 proposition. This keeps the 128-bit key, so a hit stays
exact for words up to fifteen bytes as before; only the emit is fused.

Byte-exact: `the_batched_path_matches_the_reference` drives thousands of spans through this
path, cache hits included, and compares ids to the legacy reference under debug assertions.

* perf(bpe): take the target-encode word cache and vocabulary store

u64 packed keys throughout, digest verification in the vocabulary store, and the
pipelined probe helpers (probe_slot/entry_at/resolve_foldable).

Accepts the exactness trades deliberately: a cache hit on a word over seven bytes is
2^-64, and an out-of-vocabulary pretoken can be mistaken for a vocabulary token at
2^-32, where both were previously impossible.

* perf(bpe): reserve one id per span, and key from a masked load

Two corrections to match the target-encode loop.

`output.reserve(spans.len() + MAX_INLINE_IDS)`, not two apiece. Two was measured worse:
the allocating entry point sizes its buffer at `len/4`, about one id per span, so asking
for two forced a reallocation on every call that would not otherwise have happened.

`key_and_hash_readable`: the span lies inside `chunk`, so everything up to the chunk's
end is readable and a short word's key is one unaligned masked load instead of a
head/tail stitch.

Not done, and deliberately: wiring the pipelined probe (`probe_slot`/`entry_at`/
`resolve_foldable`). Those helpers exist but the source branch does not use them, having
measured every version slower -- staging eight at a time 0.968x, carrying the next key a
word early with a `prfm` 0.96x, carrying the probe answer a word early 0.95x, pairing two
words 0.90x. The path is bound by instruction count, not latency.

* Revert "perf(bpe): carry pair ranks across multipass passes, and stop splicing"

Measured, and it does not pay: **+0.7% geomean** over tokbench's 29 gpt2 cells, inside the
+-0.8% noise floor (median of four interleaved runs, five checksum-distinct binaries, ratio
taken against gigatoken inside each run so it is immune to position drift).

It is also lopsided rather than uniformly small: chat-llama3 1.15x, agentic-tools 1.14x,
chat-deepseek 1.12x, code 1.05x, against added-normalized-dense 0.85x, hindi 0.94x,
dense 0.96x.

Taking table lookups from 41.9 per merged word to 2 per merge sounds decisive and is not,
for an arithmetic reason: it only touches the pretokens that actually merge, which is ~8% on
english. The other 92% never enter the engine, so the whole change is bounded by a small
slice of the model phase.

Not worth ~170 lines of engine rewrite plus two extra scratch buffers. The rest of the stack
-- the fused probe, u64 keys, the digest store -- is unaffected and stays.

* strip the rationale out of the code

Comment blocks recording measured dead-ends, alternatives tried and their numbers belong in
the PR, not in the source. Dropped every non-doc comment except `SAFETY` (load-bearing for
the unsafe blocks), collapsed each doc block to its first line, kept doctests, and removed
the batched-path test I had added.

Net effect on the diff against this POC: +543/-227 before, +378/-442 now -- 64 lines fewer
than the base rather than 300 more.

* drop the port's own rationale comments, keep the ones that were already there

The measured-dead-end essays and alternatives-tried notes this port added belong in the PR,
not the source: 167 comment lines removed across word_cache, bucket_vocab_store and model.

Every comment that existed in the base is preserved verbatim. The 33 base comment lines that
no longer appear are the ones whose subject the port deleted -- `PLACEMENT_HASHER` and
`DISCRIMINANT_HASHER` (gone with the u64 key), "the hasher is also stored on the struct" (the
field is gone), `entries[slot] -> (offset, length, id)` (an entry is now `(digest, id)`), and
`fold_id`'s doc (folded into `fold_id_keyed`).

`SAFETY` comments and doctests are untouched.

* wide 1.6.0 is yanked -> update cargo.toml to reference 1.5.0

* perf(bpe): probe the cache before the fold

`tokenize_spans` ran `fold_id_keyed` -- an MPHF probe, a pilot load plus a dependent entry load
into the whole vocabulary -- ahead of `probe_emit_keyed`, which is one load of the home slot and
an unconditional store of its lanes. The expensive probe went first and answered only the words
that are their own vocabulary entry, while every word the cache was about to serve paid it for
nothing. On a warm cache that is nearly all of them.

The cache now goes first and the fold answers the miss, where it still beats running the merge
engine. A folded word is inserted, so its second and later occurrences come off the cache
instead of re-probing the vocabulary.

The order follows whichever probe is cheaper, and here the fused emit already made that the
cache. On the branch behind #2313, where `900b6a48`'s digest store makes the fold cheap and the
cache is still reached through `lookup_keyed`, the same reordering measures 0.951 -- so it is the
relative cost that decides, not the order itself.

ab_giga, 4 MB, single thread, warm, median of 10 rotated rounds interleaved against this branch's
head with the LLC evicted between binaries. MB/s before -> after:

  gpt2     english 1128 -> 1182   code 609 -> 611   dense 1534 -> 1621   chinese 882 -> 902
           hindi    544 ->  595   thai 617 -> 654   korean 584 ->  610   russian 708 ->  767
           greek    670 ->  710   arabic 621 -> 676
  llama-3  english 1090 -> 1141   code 714 -> 730   dense 1412 -> 1490   chinese 914 -> 918
           hindi    835 ->  810   thai 932 -> 1003  korean 798 ->  866   russian 898 ->  968
           greek    870 ->  936   arabic 904 ->  984

  warm geomean 1.053, cold 1.039. Against c7ae7f4 on the same box this takes the branch from
  0.925 to 0.982.

Reserving two ids per span instead of one, which c7ae7f4 does, measures +0.24% here -- inside the
+-0.8% geomean noise floor -- so `975ed8df`'s one-per-span reservation stays.

Byte-exact: token counts unchanged on all 20 model x corpus pairs and equal to c7ae7f4's.
`prove_fold` only sets the bit for an entry that merging its own text reproduces, so a folded
word and a merged word give the same ids; the reorder moves which path answers, not what it
answers. 370 tests pass.

---------

Co-authored-by: Lysandre Debut <lysandre@huggingface.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants