Mischief-makers can guess the subjects being discussed with LLMs using a side-channel attack, according to Microsoft researchers. They told The Register that models from some providers, including Anthropic, AWS, DeepSeek, and Google, haven't been fixed, putting both personal users and enterprise communications at risk.

A side-channel attack monitors indirect signals, like power consumption, electromagnetic radiation, or timing, to steal cryptographic keys and other secrets. While they usually target hardware – remember Spectre, Meltdown , and all the related CPU bugs since – researchers have been poking around for side-channel vulnerabilities in LLMs .

Microsoft researchers successfully developed one such attack, named Whisper Leak, which infers the topics of prompts from encrypted LLM q

See Full Page