New attack reconstructs local LLM outputs from CPU cache traces, up to 95% success

rohanpaul_ai · x · 2026-09-11

Paper "Detokenization Leaks: Reconstructing Local LLM Outputs From Cache Traces" (arXiv:2609.06674) presents a new attack that recovers text generated by locally hosted LLMs by observing CPU cache activity during detokenization.

Related event: Side-channel attack reconstructs local LLM outputs from CPU cache(4 posts)→

Original post →

More from Safety

Safety channel →