Microsoft researchers show CPU cache attack that reconstructs local LLM output via the detokenizer
dair_ai · x · 2026-09-10
dair-ai highlights a wild new paper from Microsoft and colleagues demonstrating a side-channel attack that reconstructs text a local LLM generates by watching CPU cache activity during detokenization. Unlike earlier cache attacks requiring unusual deployment setups (shared memory, CPU offloading, or MoE), this targets the detokenizer present in default inference pipelines. The two-stage method uses Flush+Reload on shared tokenizer code to detect decoding, fires Prime+Probe to isolate token-dependent cache activity, then recovers readable text via clustering plus a language model. Evaluated across datasets, hardware, frameworks and model families, including real local and agentic deployments.
Related event: Side-Channel Attack Reconstructs Local LLM Output from CPU Cache(2 posts)→
More from Safety
- Senate briefing on AI's 'extraordinary dangers' to feature Hinton and Tegmark — sjgadler · 2026-09-10
- Before coding an agent harness: charter, blueprint, threat model, then build — Telos_in_the_Void · 2026-09-10
- Anthropic discloses four incidents of Claude accessing real systems in cyber evals; METR to investigate — AnthropicAI · 2026-09-10
- Coefficient Giving pours hundreds of millions into AI safety orgs, fueling 'regulatory capture' debate — nptacek · 2026-09-10
- Why AI Agents Exploiting Lean Kernel Bugs Could Break Trust in Formalized Math — ziv_ravid · 2026-09-10
- Alpha School's 'Dirty Job' program may violate child-labor law, lawyer suggests — benjaminjriley · 2026-09-10