• News/
  • https://www.theregister.com/2024/03/18/chatgpt_sidechannel_attack_has_easy/

ChatGPT side-channel attack has easy fix: Token obfuscation

The Register
·
Brandon Vigliarolo
·
Published Mar 18, 2024
·
Updated

Infosec in brief Almost as quickly as a paper came out last week revealing an AI side-channel vulnerability, Cloudflare researchers have figured out how to solve it: just obscure your token size. The paper [PDF], from researchers at the Offensive AI Institute at Israel's Ben Gurion University, found an issue with how all non-Google ChatGPT derivatives (including Microsoft Copilot) transmit chat sessions between LLM servers and users. When operating in streaming mode (a key component of this attack), ChatGPT and related AIs send tokens sequentially – meaning the response from the AI flows bit-by-bit to the user instead of all at once after the bot has decided how to answer. A malicious actor in the middle with the ability to intercept network traffic could sniff those LLM tokens. You may be thinking that those response tokens are encrypted, and you'd be right. Here's where the Ben Gurion researchers got crafty: they built their own specially trained LLMs designed to examine the packets and understand what they mean, with a decent degree of accuracy. "We were able to accurately reconstruct 29 percent of an AI assistant's responses and successfully infer the topic from 55 percent of them," the authors noted. Cloudflare, offers its own ChatGPT-based AIs in the form of products like Workers AI and AI Gateway, seems to have figured out how to address the issue with relative ease by padding its tokens. Cloudflare wrote that it was approached by the researchers through its bug bounty...

Read full article

Affected Software

5 affected components
OpenAI Chatgpt
Microsoft Copilot
Cloudflare Workers AI
Cloudflare AI Gateway
Roblox Roblox Platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly identified side-channel vulnerability in AI systems and the proposed solution of token obfuscation.

2

What security implications are discussed regarding AI systems?

The article highlights how the side-channel attack can potentially expose sensitive information in AI systems like ChatGPT.

3

What solutions are recommended to mitigate the vulnerability?

The recommended solution is to obscure the token size used within the AI systems to prevent the exploitation of the side-channel attack.

4

Which products are specifically affected by the side-channel attack?

The affected products include OpenAI's ChatGPT, Microsoft's Copilot, Cloudflare's Workers AI and AI Gateway, as well as Roblox Platform.

5

Who identified the side-channel vulnerability in AI?

The vulnerability was revealed in a paper by researchers at the Offense & Defense Lab.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203