logo

Mitigating a token-length side-channel attack in our AI products

ID: 51e97ab5-2b8f-5b42-99f4-37204b4b0776

STIX ID: report--51e97ab5-2b8f-5b42-99f4-37204b4b0776

Feed Name: Cloudflare Blog

Threat Score
35/100

Date Published: 2024-03-14

Date Updated: 2026-04-27

Author: Celso Martinho

...
...

Cloudflare describes a recently reported token-length side-channel attack on streaming LLM responses, where an on-path attacker can infer per-token lengths from encrypted packet sizes and partially reconstruct assistant outputs (researchers report ~29% reconstruction and ~55% topic inference). Cloudflare validated the research, found variability in real-world accuracy, and rolled out mitigations by adding random-length padding to streaming JSON responses in Workers AI and AI Gateway, automatically protecting customers; no malicious exploitation was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.