Side-Channel Attack Reconstructs Local LLM Output from CPU Cache

A new Microsoft-backed paper shows attackers can reconstruct locally deployed LLM outputs by monitoring CPU cache activity during detokenization, without needing shared memory or CPU offloading.

2026-09-09 ~ 2026-09-10 · 2 related posts