DEF CON 32 - Your AI Assistant has a Big Mouth:  A New Side Channel Attack - Yisroel Mirsky

DEF CON 32 - Your AI Assistant has a Big Mouth: A New Side Channel Attack - Yisroel Mirsky

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:55

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Researchers have discovered a new side channel attack against AI assistants that enables adversaries to read encrypted response traffic by analyzing token lengths in network packets 0:34.

Key Takeaways:
• The vulnerability stems from AI services sending each token as a separate packet with no padding, allowing attackers to count characters in each token 3:16
• Attackers can extract token length sequences from network traffic and use AI models to translate them back to plain text with 55% accuracy for first sentences 7:00
• Nearly every major AI service had this vulnerability as of February 2024, potentially exposing sensitive personal information like medical questions and relationship advice 11:21
• The research team developed a tool called GPT Keylogger and disclosed the vulnerability, with vendors implementing defenses like packet padding 34:56

This discovery highlights how even seemingly minor details in data transmission can create significant security vulnerabilities in AI systems 38:10.

Sources:

  • 0:34 Introduction to the side channel attack
  • 3:16 Explanation of how tokens are transmitted as separate packets
  • 7:00 Using AI models to translate token lengths to text
  • 11:21 Vulnerability prevalence in AI services
  • 34:56 Development of GPT Keylogger tool and vendor responses

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello Defcon thank you so much for being here it's like the second to last talk it's a great turn out I'm very honored to be here my name is yel mki I'm a Zuckerman faculty scholar at Ben gurin University and head of the offensive AI research lab there and uh with me here today are my brilliant graduate students who will be coming up on stage also to present they did all the hard work there's Daniel eisenstein and Roy Vice in collaboration with guy who couldn't make it okay so today we're going to talk about a new side Channel attack against AI assistance that enables adversaries to read encrypted response traffic such as responses from chat GPT okay so I'm not going to go into you know what are AI assistants you guys all know this very well you have open ai's chat GPT you have Google's Ge…