
DEF CON 32 - Your AI Assistant has a Big Mouth: A New Side Channel Attack - Yisroel Mirsky
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:55
Researchers have discovered a new side channel attack against AI assistants that enables adversaries to read encrypted response traffic by analyzing token lengths in network packets 0:34.
Key Takeaways:
• The vulnerability stems from AI services sending each token as a separate packet with no padding, allowing attackers to count characters in each token 3:16
• Attackers can extract token length sequences from network traffic and use AI models to translate them back to plain text with 55% accuracy for first sentences 7:00
• Nearly every major AI service had this vulnerability as of February 2024, potentially exposing sensitive personal information like medical questions and relationship advice 11:21
• The research team developed a tool called GPT Keylogger and disclosed the vulnerability, with vendors implementing defenses like packet padding 34:56
This discovery highlights how even seemingly minor details in data transmission can create significant security vulnerabilities in AI systems 38:10.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hello Defcon thank you so much for being here it's like the second to last talk it's a great turn out I'm very honored to be here my name is yel mki I'm a Zuckerman faculty scholar at Ben gurin University and head of the offensive AI research lab there and uh with me here today are my brilliant graduate students who will be coming up on stage also to present they did all the hard work there's Daniel eisenstein and Roy Vice in collaboration with guy who couldn't make it okay so today we're going to talk about a new side Channel attack against AI assistance that enables adversaries to read encrypted response traffic such as responses from chat GPT okay so I'm not going to go into you know what are AI assistants you guys all know this very well you have open ai's chat GPT you have Google's Ge…