Similarity Is Not Validity: Defending LLM Semantic Caches Against Poisoning

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of LLM semantic caches to poisoning attacks arising from their exclusive reliance on embedding similarity retrieval, which introduces an information gap between retrieval similarity and answer validity. Grounded in information bottleneck theory, this work reveals the lack of discriminability in embedding representations and leverages raw text to recover critical information. By analyzing the rewrite-residual structure of adversarial queries, it proposes a novel defense mechanism integrating deletion gain computation with answer verification. The proposed approach successfully intercepts 82.0% to 98.2% of poisoned entries at a 5% false positive rate while incurring negligible service overhead, substantially enhancing the security of semantic caching systems.
📝 Abstract
Semantic caches reduce LLM serving costs by reusing previously generated answers for semantically similar queries. However, retrieval is based solely on embedding similarity between the incoming query and cached queries. This design enables cache poisoning: an attacker can cache a malicious response under a query with high cosine similarity to benign requests. The vulnerability stems from a gap between retrieval similarity and answer validity. From an information-bottleneck perspective, query embeddings can lose information needed to distinguish valid from invalid cache hits, which limits any matching algorithm that uses only these embeddings. We propose a novel defense that recovers this necessary information from the raw text of the cache key. Across poisoning attacks, adversarial queries share a rewrite-residual structure: they pair a rewrite of the target query with residual content. The rewrite maintains high similarity, while the residual elicits the malicious response. Deleting the residual makes the remaining rewrite more similar to the incoming query. We exploit this structure using Deletion Gain to search shortened variants of the cached query for similarity gains, and an Answer Check to test whether the removed text contributes to the stored answer. We prove that Deletion Gain stays positive when a deletion leaves text close enough to the rewrite, and we search for such deletions with a sliding window. Across three poisoning attack classes, our defense blocks 82.0% to 98.2% of poisoned entries at a 5% false-positive rate, with negligible serving overhead.
Problem

Research questions and friction points this paper is trying to address.

semantic cache
cache poisoning
large language models
embedding similarity
security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Semantic Cache Poisoning
Information Bottleneck
Deletion Gain
Rewrite-Residual Structure
Answer Check
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Zihan Zhang
Zihan Zhang
Southern University of Science and Technology
HCI
S
Shuangjie Yao
The Hong Kong University of Science and Technology
Zesen Liu
Zesen Liu
Ph.D. Student, HKUST
Security
Z
Zhixiang Zhang
The Hong Kong University of Science and Technology
W
Wai Ip Lai
The Hong Kong University of Science and Technology
D
Dung Hiu Hilton Yeung
The Hong Kong University of Science and Technology
C
Chun Kit Zhang
The Hong Kong University of Science and Technology
Fuchen Ma
Fuchen Ma
Tsinghua University
Yuanyuan Yuan
Yuanyuan Yuan
ETH Zurich
Security
Yu Jiang
Yu Jiang
Tsinghua University
Program Analysis and SynthesisCyber-Physical System
Dongdong She
Dongdong She
Hong Kong University of Science and Technology
SecurityMachine LearningProgram AnalysisFuzzing