← Back to brief
Policy & SafetyOfficialPreprintarXiv Cryptography and Security

SparSEEty: Token Extraction Attack Reveals Side-Channel Vulnerabilities in Sparsity-Optimized LLM Serving

A new preprint introduces SparSEEty, a side-channel attack that can extract user prompt and response tokens from large language model (LLM) serving systems that exploit activation sparsity for efficiency. The attack works even when the LLM is protected inside an Intel TDX confidential virtual machine, reconstructing tokens with high accuracy (BLEU >0.95) and incurring modest overhead. This demonstrates that certain performance optimizations in LLM serving can unintentionally leak sensitive information.

Why it matters: The work highlights a significant new security risk for LLM deployments that use sparsity-based optimizations, with implications for user privacy and cloud AI service design.

Full story at: arXiv Cryptography and Security