Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory Forensics
Haichuan Xu, David Oygenblik, Runze Zhang, Mingxuan Yao, Muhammad Ibrahim, Brendan Saltaformaggio
Abstract
Advances in edge computing devices have enabled local large language model (LLM) apps to execute entirely on-device, powering tasks such as document summarization and virtual assistance while preserving user privacy. However, this also removes centralized logging and enforcement, allowing adversaries to fine-tune or deploy modified models that generate malicious content. When such apps are used in planning crimes, it is hard for forensic investigators to gather evidences because disk logs from app storage are cleared once conversation histories are deleted from the UI by suspects. Existing memory forensics techniques also cannot reconstruct the context embeddings retained within the LLM runtime states. We present ORISA, a memory forensics framework for recovering and rehosting deleted conversation contexts from local LLM apps. ORISA leverages the batch tokens and key-value (KV) caches preserved in process memory to reconstruct token sequences and restore session-level attention states. ORISA recovers previous conversations and outputs a rehosted app-agnostic session that remembers forgotten context from the original session, allowing investigators to reveal suspect's prior interactions and ask additional information using the live session. We evaluated ORISA across 60 session configurations involving 10 Android local LLM apps and 3 model architectures. ORISA recovered 100% of tokens and KV cache tensors within the active context window, and an average of 32.60% and 38.59% more forgotten context. ORISA's rehosted sessions revealed an average of 169.6% knowledge compared to the original session.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d4551c98-cf16-4373-ad1f-a51cb3906ffaRelated papers
- SemCache: Semantic-Aware Cache Sharing for Efficient Multi-User LoRA-Adapted LLM Inference at the EdgeTao Ren, Yiming Yao, Zheyuan Hu, Jianwei NiuINFOCOM 2026 · 1 citation
- MobiLoRA: Accelerating LoRA-based LLM Inference on Mobile Devices via Context-aware KV Cache OptimizationBorui Li, Yitao Wang, Haoran Ma, Ligeng Chen et al.ACL 2025 · 6 citations
- AI Psychiatry: Forensic Investigation of Deep Learning Networks in Memory ImagesDavid Oygenblik, Carter Yagemann, Joseph Zhang, Arianna Mastali et al.USENIX Security 2024 · 6 citations
- Enabling On-Device Large Language Model Personalization with Self-Supervised Data Selection and SynthesisRuiyang Qin, Jun Xia, Zhenge Jia, Meng Jiang et al.DAC 2024 · 17 citations
- Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory ImagesBrendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang, Dongyan Xu et al.USENIX Security 2016 · 32 citations
