• News/
  • https://www.theregister.com/2025/11/11/llm_sidechannel_attack_microsoft_researcher/

LLM side-channel attack could allow snoops to guess topic

The Register
·
Jessica Lyons
·
Published Nov 11, 2025
·
Updated

Updated Mischief-makers can guess the subjects being discussed with LLMs using a side-channel attack, according to Microsoft researchers. They told The Register that models from some providers, including Anthropic, AWS, DeepSeek, and Google, haven't been fixed, putting both personal users and enterprise communications at risk. A side-channel attack monitors indirect signals, like power consumption, electromagnetic radiation, or timing, to steal cryptographic keys and other secrets. While they usually target hardware – remember Spectre, Meltdown, and all the related CPU bugs since – researchers have been poking around for side-channel vulnerabilities in LLMs. Microsoft researchers successfully developed one such attack, named Whisper Leak, which infers the topics of prompts from encrypted LLM queries by analyzing packet size and timing patterns in streaming responses. Streaming models send responses to users incrementally, in small chunks or tokens, as opposed to sending the complete responses all at once. This makes them susceptible to an attacker-in-the-middle scenario, where someone with the ability to intercept network traffic could sniff those LLM tokens. "Cyberattackers in a position to observe the encrypted traffic (for example, a nation-state actor at the internet service provider layer, someone on the local network, or someone connected to the same Wi-Fi router) could use this cyberattack to infer if the user's prompt is on a specific topic," researchers Jonathan Bar ...

Read full article

Affected Software

9 affected components
Anthropic Claude
Amazon Nova
Alibaba Qwen
DeepSeek DeepSeek
Lambda Labs Gemini
Microsoft Azure
OpenAI ChatGPT
Mistral Mistral
xAI xAI
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a side-channel attack that could allow attackers to infer the topics being discussed with large language models (LLMs).

2

What security implications are discussed in the article?

The researchers highlight that this attack could enable unauthorized parties to glean sensitive information from conversations involving LLMs.

3

What types of software or products are affected by this vulnerability?

The vulnerability affects large language models from providers such as Anthropic, AWS, DeepSeek, and Google.

4

Who conducted the research on the LLM side-channel attack?

Microsoft researchers are the ones who identified and reported on the side-channel attack affecting LLMs.

5

Can this attack be performed remotely or does it require local access?

The article suggests that the attack can be performed remotely, potentially increasing the risk to users interacting with LLMs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203