LATIDIA · Ciberseguridad
Su modelo tiene fugas: transferencia de información encubierta a través de flujos residuales de LLM
arXiv: 2609.27996v1Tipo de anuncio: nuevo Resumen: las organizaciones sensibles a la privacidad pueden ejecutar grandes modelos de lenguaje (LLM) en entornos restringidos o con huecos de aire mientras exportan artefactos de diagnóstico seleccionados. Mostramos que un
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.27996v1 Announce Type: new Abstract: Privacy-sensitive organizations may run large language models (LLMs) in restricted or air-gapped environments while exporting selected diagnostic artifacts. We show that a compromised runtime component can hide sensitive information in intermediate activations that are allowed to leave the restricted environment. An offline observer can recover this information with a simple linear decoder. The attack requires no model retraining or weight modification, no attacker-controlled egress, and no control over the recorder or transfer process. We introduce a residual-stream covert-channel attack that maps messages to codewords and injects them into an intermediate residual stream through a compromised runtime hook. To maintain recoverability, the injection strength is scaled