Recovering encrypted LLM reasoning traces leaks sensitive data
dl_weekly · x · 2026-08-26
A security researcher reproduced an attack targeting encrypted LLM reasoning traces. The study shows that vendors likely use shared encryption keys across users, sessions, and models, allowing attackers to replay encrypted blobs to weaker, more jailbreak-prone models to decode the original reasoning. Researchers analyzed 315,320 public reasoning blocks and recovered 367 PII items and 182 credentials, including API keys and passwords. This indicates that sharing session files containing encrypted blobs poses a significant information leakage risk.
More from Safety
- Researcher Uses GPT-5.6 to Break Block Cipher MERIDIAN — evilsocket · 2026-08-26
- Foresight CEO: Open Science Needs Independent Secure Compute Clusters — allisondman · 2026-08-26
- Stanford Report: California Data Brokers Fail to Comply with Delete Act — StanfordHAI · 2026-08-26
- Stanford Policy Brief: Regulating Data Brokers in the Age of AI — StanfordHAI · 2026-08-26
- AI Copyright Problem: Defining Boundaries Between Retrieval and Abstraction — HotEstablishment7184 · 2026-08-26
- Multiple Organizations Form PACT AI to Build the AI Assurance Ecosystem — Miles_Brundage · 2026-08-26