← Back to brief
Policy & SafetyOfficialPreprintarXiv Cryptography and Security

LeakyLMs Attack Reveals Proprietary Model Details via Token Timing Side Channels

A new preprint introduces LeakyLMs, a set of attacks that can infer proprietary language model architectures and deployment optimizations by analyzing per-token generation timing from remote APIs. The attacks can detect inference techniques such as speculative decoding and estimate architectural parameters like the number of layers and attention heads. Experiments show that the correct architecture is often among the top-10 guesses, highlighting a potential security risk for commercial AI providers.

Why it matters: This work demonstrates that timing side channels can expose sensitive model details, raising security concerns for AI systems deployed via public APIs.

Full story at: arXiv Cryptography and Security