Think your AI chats are private? Think again. đŸš©

A new side-channel attack called the "Whisper Leak" allows hackers to infer your conversations even with encryption.

#aichat #privacy #WhisperLeak

https://youtu.be/BngIOAtL42M

Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted Traffic

Microsoft’s Whisper Leak shows encrypted AI chats can secretly reveal user topics through subtle traffic patterns.

The Hacker News

Whisper-Leak-Angriff
Large Language Models (LLMs) werden zunehmend in sensiblen Bereichen eingesetzt, darunter Gesundheitswesen, Rechtsdienstleistungen und vertrauliche Kommunikation, wo der Datenschutz von grĂ¶ĂŸter Bedeutung ist. Die neue Bedrohung: Whisper Leak, ein Side‑Channel‑Angriff, der die Themen von Nutzer‑Prompts aus verschlĂŒsseltem LLM‑Verkehr ableitet, indem er PaketgrĂ¶ĂŸen‑ und Zeitmuster in Streaming‑Antworten analysiert. Obwohl TLS‑VerschlĂŒsselung den Inhalt schĂŒtzt, fallen zu viele Metadaten-Muster vom "TLS-Laster". Werde eine kritische Menge an "Verlustdaten" ĂŒberschritten, sei eine Themenklassifizierung möglich.
Mehr: https://maniabel.work/archiv/158

#WhisperLeak

Whisper-Leak-Angriff – maniabel.work

Entdecken Sie, was Sie fĂŒr die Sicherheit und den Schutz Ihrer Daten selbst tun können. <meta charset=

🧠 “Whisper Leak” can infer encrypted LLM chat topics via traffic pattern analysis.

Partial fixes by Microsoft, OpenAI & xAI - others remain vulnerable.
https://www.technadu.com/llm-side-channel-attack-whisper-leak-exposes-encrypted-communications/613063/

#AIsecurity #WhisperLeak #CyberThreat

Microsoft disclosed a new AI privacy threat, “Whisper Leak” — a side-channel attack that can reveal AI chat topics through encrypted traffic analysis.
Even HTTPS encryption isn’t enough if packet sizes & timing give away what’s being discussed.
Providers like OpenAI, Mistral, and Microsoft are adding random padding to counter the issue.
Are current LLM streaming designs too leaky for enterprise adoption?
💬 Share your thoughts and follow @technadu for ongoing AI security updates.

#InfoSec #AIPrivacy #WhisperLeak #CyberSecurity #Encryption #LLMSecurity #TechNadu #DataProtection

"Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model conversation topics despite encryption protections under certain circumstances.

This leakage of data exchanged between humans and streaming-mode language models could pose serious risks to the privacy of user and enterprise communications, the company noted. The attack has been codenamed Whisper Leak.

"Cyber attackers in a position to observe the encrypted traffic (for example, a nation-state actor at the internet service provider layer, someone on the local network, or someone connected to the same Wi-Fi router) could use this cyber attack to infer if the user's prompt is on a specific topic," security researchers Jonathan Bar Or and Geoff McDonald, along with the Microsoft Defender Security Research Team, said.

Put differently, the attack allows an attacker to observe encrypted TLS traffic between a user and LLM service, extract packet size and timing sequences, and use trained classifiers to infer whether the conversation topic matches a sensitive target category."

https://thehackernews.com/2025/11/microsoft-uncovers-whisper-leak-attack.html

#AI #GenerativeAI #CyberSecurity #Microsoft #WhisperLeak #LLMs #Encryption

Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted Traffic

Microsoft’s Whisper Leak shows encrypted AI chats can secretly reveal user topics through subtle traffic patterns.

The Hacker News

Interessant: auch eine verschlĂŒsselte Kommunikation ĂŒbers Netz mit einem #Chatbot bietet wohl genĂŒgend Anhaltspunkte, um von außen auf bestimmte Themen zu schließen.

Nicht, dass das Teilen von Themen mit einer "#KI" an sich schon reichlich naiv wÀre.

(via @nopatience)

Englisch:

https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/

#WhisperLeak

​​Whisper Leak: A novel side-channel attack on remote language models | Microsoft Security Blog

Understand the risks of encrypted AI traffic exposure and explore practical steps users and cloud providers can take to stay secure. Learn more.

Microsoft Security Blog