What Was Your Prompt? A Remote Keylogging Attack on AI Assistants
Roy Weiss, Daniel Ayzenshteyn, Guy Amit, Yisroel Mirsky
摘要
AI assistants are becoming an integral part of society, used for asking advice or help in personal and confidential issues. In this paper, we unveil a novel side-channel that can be used to read encrypted responses from AI Assistants over the web: the token-length side-channel. We found that many vendors, including OpenAI and Microsoft, have this side-channel. However, inferring the content of a response from a token-length sequence alone proves challenging. This is because tokens are akin to words, and responses can be several sentences long leading to millions of grammatically correct sentences. In this paper, we show how this can be overcome by (1) utilizing the power of a large language model (LLM) to translate these sequences, (2) providing the LLM with inter-sentence context to narrow the search space and (3) performing a known-plaintext attack by fine-tuning the model on the target model's writing style. Using these methods, we were able to accurately reconstruct 29% of an AI assistant's responses and successfully infer the topic from 55% of them. To demonstrate the threat, we performed the attack on OpenAI's ChatGPT-4 and Microsoft's Copilot on both browser and API traffic.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Memory Backdoor Attacks on Neural NetworksEden Luzon, Guy Amit, Roy Weiss, Torsten Krauß 等NDSS 2026 · 被引用 3 次
- Keytar: Practical Keystroke Timing Attacks and Input ReconstructionMufan Qiu, Lihsuan Chuang, Dohhyun Kim, Huaizhi Qu 等S&P 2026 · 被引用 2 次
- IOValve: Leakage-Free I/O Sandbox for Large-Scale Untrusted Data ProcessingSangho Lee, Jules Drean, Yue Tan, Marcus PeinadoCCS 2025 · 被引用 1 次
- Network-Level Prompt and Trait Leakage in Local Research AgentsHyejun Jeong, Mohammadreza Teymoorianfard, Abhinav Kumar, Amir Houmansadr 等USENIX Security 2026 · 被引用 1 次
- I Know What You Said: Unveiling Hardware Cache Side-Channels in Local Large Language Model InferenceZibo Gao, Junjie Hu, Feng Guo, Yixin Zhang 等USENIX Security 2025
它引用的顶会 Paper8
- Quantifying Memorization Across Neural Language ModelsNicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee 等ICLR 2023 · 被引用 158 次
- DeepSniffer: A DNN Model Extraction Framework Based on Learning Architectural HintsXing Hu, Ling Liang, Shuangchen Li, Lei Deng 等ASPLOS 2020 · 被引用 128 次
- Enhancing Chat Language Models by Scaling High-quality Instructional ConversationsNing Ding, Yulin Chen, Bokai Xu, Yujia Qin 等EMNLP 2023 · 被引用 95 次
- Privacy Side Channels in Machine Learning SystemsEdoardo Debenedetti, Giorgio Severi, Milad Nasr, Christopher A. Choquette-Choo 等USENIX Security 2024 · 被引用 52 次
- Reverse-Engineering Deep Neural Networks Using Floating-Point Timing Side-ChannelsCheng Gongye, Yunsi Fei, Thomas WahlDAC 2020 · 被引用 39 次
相关 Paper
- From Length to Content: Token-Length Side-Channel Attacks on LLM API Merged OutputsSijia Li, Tianyu Cui, Miao Chen, Xinjie Lin 等USENIX Security 2026
- Reconstruct Your Previous Conversations! Comprehensively Investigating Privacy Leakage Risks in Conversations with GPT ModelsJunjie Chu, Zeyang Sha, Michael Backes, Yang ZhangEMNLP 2024 · 被引用 3 次
- Combing for Credentials: Active Pattern Extraction from Smart ReplyBargav Jayaraman, Esha Ghosh, Melissa Chase, Sambuddha Roy 等S&P 2024 · 被引用 11 次
- I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM ServingGuanlong Wu, Zheng Zhang, Yao Zhang, Weili Wang 等NDSS 2025
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsYigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann 等S&P 2026 · 被引用 12 次
