Detokenization Leaks: Reconstructing Local LLM Outputs From Cache Traces

📅 2026-09-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
本文提出一种通过观察CPU缓存活动来重建本地LLM生成文本的新攻击方法,利用Flush+Reload和Prime+Probe技术获取并处理缓存信号以恢复文本。
📝 Abstract
We present a new attack that reconstructs the text generated by locally hosted LLMs by observing CPU cache activity during detokenization. Unlike prior attacks that rely on deployment-specific assumptions, such as shared data memory, CPU offloading, or Mixture-of-Experts architectures, our approach targets the detokenizer, a component used in default LLM inference pipelines. To obtain clean signals, we use Flush+Reload on shared tokenizer code to detect when decoding occurs, which lets us perform Prime+Probe at the right moment and isolate token-dependent cache activity. We then apply a clustering-and-language-model pipeline to recover text from noisy cache observations. We evaluate the attack across multiple datasets, hardware platforms, inference frameworks, and model families, and show that it can recover semantically accurate outputs from real-world local LLM deployments, including agentic systems. This vulnerability is particularly significant because the most widely used tokenizer implementations are susceptible to the attack and are embedded in many popular local LLM products and agent frameworks, including systems such as OpenClaw (which we demonstrate), substantially broadening the practical attack surface.
Problem

Research questions and friction points this paper is trying to address.

Detokenization
Cache Traces
LLMs
Text Reconstruction
Security Vulnerability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Detokenization
Cache Traces
Flush+Reload
Prime+Probe
R
Roy Weiss
Ben Gurion University
B
Benyamin Konstantinov
Ben Gurion University
Eitam Sheetrit
Eitam Sheetrit
Ph.D., Software and Information Systems Engineering in Ben-Gurion University
T
Tomer Simon
Microsoft Security
Y
Yisroel Mirsky
Ben Gurion University