logo

Side-Channel Attacks Against LLMs

ID: ca3d5cc0-743a-5197-aa59-8cdb31010b6c

STIX ID: report--ca3d5cc0-743a-5197-aa59-8cdb31010b6c

Feed Name: Schneier on Security

Threat Score
65/100

Date Published: 2026-02-17

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This post summarizes three academic papers exposing side-channel attacks against LLMs: remote timing attacks that infer conversation topics and (on open-source systems) recover PII; speculative-decoding leakage that fingerprints queries and can exfiltrate datastore tokens; and "Whisper Leak," which classifies prompt topics from encrypted traffic with very high accuracy across many models. The works demonstrate high-precision leakage from metadata (timing/packet sizes/iteration counts), evaluate mitigations (padding, batching, packet injection), and note partial defenses and responsible disclosure with some provider collaboration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.