9 papers
Steganography Without Modification: Hidden Communication via LLM Seeds
Felix Mächtle, Jonas Sander, Sebastian Berndt +3
We demonstrate that widely deployed Large Language Model (LLM) inference stacks harbor a steganographic channel that requires no modification to model weights, sampling code, or ou…
DRAMatic Speedup: Accelerating HE Operations on a Processing-in-Memory System
Niklas Klinger, Jonas Sander, Peterson Yuhala +2
Homomorphic encryption (HE) is a promising technology for confidential cloud computing, as it allows computations on encrypted data. However, HE is computationally expensive and of…
TrEEStealer: Stealing Decision Trees via Enclave Side Channels
Jonas Sander, Anja Rabich, Nick Mahling +5
Today, machine learning is widely applied in sensitive, security-related, and financially lucrative applications. Model extraction attacks undermine current business models where a…
BarkBeetle: Stealing Decision Tree Models with Fault Injection
Qifan Wang, Jonas Sander, Minmin Jiang +2
Machine learning models, particularly decision trees (DTs), are widely adopted across various domains due to their interpretability and efficiency. However, as ML models become inc…
Silenzio: Secure Non-Interactive Outsourced MLP Training
Jonas Sander, Thomas Eisenbarth
Outsourcing ML training to cloud-service-providers presents a compelling opportunity for resource constrained clients, while it simultaneously bears inherent privacy risks. We intr…
Prompt Pirates Need a Map: Stealing Seeds helps Stealing Prompts
Felix Mächtle, Ashwath Shetty, Jonas Sander +3
Diffusion models have significantly advanced text-to-image generation, enabling the creation of highly realistic images conditioned on textual prompts and seeds. Given the consider…