4 papers · 1 filter
Detokenization Leaks: Reconstructing Local LLM Outputs From Cache Traces
Roy Weiss, Benyamin Konstantinov, Eitam Sheetrit +2
We present a new attack that reconstructs the text generated by locally hosted LLMs by observing CPU cache activity during detokenization. Unlike prior attacks that rely on deploym…
Memory Backdoor Attacks on Neural Networks
Eden Luzon, Guy Amit, Roy Weiss +3
Neural networks are often trained on proprietary datasets, making them attractive attack targets. We present a novel dataset extraction method leveraging an innovative training tim…
The Best Defense is a Good Offense: Countering LLM-Powered Cyberattacks
Daniel Ayzenshteyn, Roy Weiss, Yisroel Mirsky
As large language models (LLMs) continue to evolve, their potential use in automating cyberattacks becomes increasingly likely. With capabilities such as reconnaissance, exploitati…
What Was Your Prompt? A Remote Keylogging Attack on AI Assistants
Roy Weiss, Daniel Ayzenshteyn, Guy Amit +1
AI assistants are becoming an integral part of society, used for asking advice or help in personal and confidential issues. In this paper, we unveil a novel side-channel that can b…