← Back to brief
Policy SafetyOfficialPreprintarXiv Cryptography and Security

HijackKV: Attack Exposes Security Flaw in Position-Independent KV Cache Reuse for LLMs

Jul 23, 2026

A new preprint introduces HijackKV, an attack that exploits position-independent key-value (KV) cache reuse in large language models (LLMs). By injecting a malicious prefix, attackers can manipulate model outputs even when the input appears benign, with the attack persisting across multi-turn interactions and transferring between models. The study reports a high success rate and demonstrates the vulnerability under realistic deployment conditions.

Why it matters: This work highlights a significant security risk in widely adopted LLM inference optimizations, raising concerns about the safe deployment of KV cache reuse techniques.

Full story at: arXiv Cryptography and Security