I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving
Guangheng Wu, Zheng Zhang, Jianyu Niu, Weili Wang, Yao Zhang, Ye Wu, Yinqian Zhang
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
Large Language Models (LLMs), which laid the groundwork for Artificial General Intelligence (AGI), have recently gained significant traction in academia and industry due to their disruptive applications.In order to enable scalable applications and efficient resource management, various multitenant LLM serving frameworks have been proposed, in which the LLM caters to the needs of multiple users simultaneously.One notable mechanism in recent works, such as SGLang and vLLM, is sharing the Key-Value (KV) cache for identical token sequences among multiple users, saving both memory and computation.This paper presents the first investigation on security risks associated with multi-tenant LLM serving.We show that the state-of-the-art mechanisms of KV cache sharing may lead to new side channel attack vectors, allowing unauthorized reconstruction of user prompts and compromising sensitive user information among mutually distrustful users.Specifically, we introduce our attack, PROMPTPEEK, and apply it to three scenarios where the adversary, with varying degrees of prior knowledge, is capable of reverse-engineering prompts from other users.This study underscores the need for careful resource management in multitenant LLM serving and provides critical insights for future security enhancement.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AINetwork Packet Processing and Optimization
IPv6, Mobility, Handover, Networks, Security · Caching and Content Delivery
参考文献 0
引用本文 11
按被引量排序,此处列出前 3 条