InputSnatch: Stealing Input in LLM Services via Timing Side-Channel Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zheng, Xinyao, Han, Husheng, Shi, Shangyi, Fang, Qiyan, Du, Zidong, Hu, Xing, Guo, Qi
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909408366166016
author Zheng, Xinyao
Han, Husheng
Shi, Shangyi
Fang, Qiyan
Du, Zidong
Hu, Xing
Guo, Qi
author_facet Zheng, Xinyao
Han, Husheng
Shi, Shangyi
Fang, Qiyan
Du, Zidong
Hu, Xing
Guo, Qi
contents Large language models (LLMs) possess extensive knowledge and question-answering capabilities, having been widely deployed in privacy-sensitive domains like finance and medical consultation. During LLM inferences, cache-sharing methods are commonly employed to enhance efficiency by reusing cached states or responses for the same or similar inference requests. However, we identify that these cache mechanisms pose a risk of private input leakage, as the caching can result in observable variations in response times, making them a strong candidate for a timing-based attack hint. In this study, we propose a novel timing-based side-channel attack to execute input theft in LLMs inference. The cache-based attack faces the challenge of constructing candidate inputs in a large search space to hit and steal cached user queries. To address these challenges, we propose two primary components. The input constructor employs machine learning techniques and LLM-based approaches for vocabulary correlation learning while implementing optimized search mechanisms for generalized input construction. The time analyzer implements statistical time fitting with outlier elimination to identify cache hit patterns, continuously providing feedback to refine the constructor's search strategy. We conduct experiments across two cache mechanisms and the results demonstrate that our approach consistently attains high attack success rates in various applications. Our work highlights the security vulnerabilities associated with performance optimizations, underscoring the necessity of prioritizing privacy and security alongside enhancements in LLM inference.
format Preprint
id arxiv_https___arxiv_org_abs_2411_18191
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle InputSnatch: Stealing Input in LLM Services via Timing Side-Channel Attacks
Zheng, Xinyao
Han, Husheng
Shi, Shangyi
Fang, Qiyan
Du, Zidong
Hu, Xing
Guo, Qi
Cryptography and Security
Large language models (LLMs) possess extensive knowledge and question-answering capabilities, having been widely deployed in privacy-sensitive domains like finance and medical consultation. During LLM inferences, cache-sharing methods are commonly employed to enhance efficiency by reusing cached states or responses for the same or similar inference requests. However, we identify that these cache mechanisms pose a risk of private input leakage, as the caching can result in observable variations in response times, making them a strong candidate for a timing-based attack hint. In this study, we propose a novel timing-based side-channel attack to execute input theft in LLMs inference. The cache-based attack faces the challenge of constructing candidate inputs in a large search space to hit and steal cached user queries. To address these challenges, we propose two primary components. The input constructor employs machine learning techniques and LLM-based approaches for vocabulary correlation learning while implementing optimized search mechanisms for generalized input construction. The time analyzer implements statistical time fitting with outlier elimination to identify cache hit patterns, continuously providing feedback to refine the constructor's search strategy. We conduct experiments across two cache mechanisms and the results demonstrate that our approach consistently attains high attack success rates in various applications. Our work highlights the security vulnerabilities associated with performance optimizations, underscoring the necessity of prioritizing privacy and security alongside enhancements in LLM inference.
title InputSnatch: Stealing Input in LLM Services via Timing Side-Channel Attacks
topic Cryptography and Security
url https://arxiv.org/abs/2411.18191