arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

HijackKV:位置无关的键值缓存重用中的新威胁

HijackKV: New Threat in Position-Independent KV Cache Reuse

Yichi Zhang, Zhiqi Wang, Huan Zhang, Yuchen Yang

arXiv 2607.19957首次发表:更新:

发表机构

The Pennsylvania State University; University of Illinois Urbana-Champaign(宾夕法尼亚州立大学; 伊利诺伊大学厄巴纳-香槟分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究位置无关的KV缓存重用中的新威胁KV缓存劫持,介绍HIJACKKV攻击框架,该框架可优化攻击者控制的前缀,使受污染的KV在特定条件下劫持模型行为,单次尝试成功率达94%,还为构建安全KV重用系统提供设计见解。

AI 中文摘要

键值(KV)缓存可减少大语言模型(LLMs)中的推理延迟。传统基于前缀的重用在推理请求中的缓存命中率较低,因为它需要精确的令牌和位置匹配。为提高效率,近期系统优化引入位置无关的KV重用,允许相同文本块出现时重用KV缓存,而不论其在序列中的位置。我们发现这种设计引入了新威胁——KV缓存劫持。由于KV缓存通过令牌匹配检索,但编码了其最初计算的上下文,与看似良性的令牌块相关联的KV可能编码攻击者控制的前缀。当在受害者查询中重用时,即使输入中没有攻击者控制的文本,这种受污染的KV也会悄悄劫持模型行为。我们引入了HIJACKKV,第一个系统利用此漏洞的攻击框架,展示了其严重性和实用性。HIJACKKV优化攻击者控制的前缀,使为后续常见良性文本计算的KV编码攻击者的目标,同时文本对未来缓存命中保持不变。HIJACKKV在单次尝试中平均成功率达到94%,在包括低命中率(10%)和频繁重新计算(50%)的现实约束下仍然有效,在多轮交互中持续存在,并在黑盒设置中跨模型转移。我们还为构建安全的KV重用系统提供了设计见解。

英文摘要

Key-Value (KV) cache reduces inference latency in large language models (LLMs). Traditional prefix-based reuse has low cache hit rates across inference requests because it requires exact token and position matches. To improve efficiency, recent system optimizations introduce position-independent KV reuse, allowing KV cache to be reused whenever identical text chunks appear, regardless of their position in the sequence. We show this design introduces a new threat, KV Cache Hijacking. Since KV caches are retrieved by token match but encode the context in which they were originally computed, the KV tied to a benign-looking token chunk may encode an attacker-controlled prefix. When later reused in a victim query, this contaminated KV silently hijacks the model's behavior, even if no attacker-controlled text appears in the input. We introduce HIJACKKV, the first attack framework that systematically exploits this vulnerability, demonstrating its severity and practicality. HIJACKKV optimizes an attacker-controlled prefix, so that the KV computed for a subsequent common benign text encodes the attacker's goal, while the text remains unchanged for future cache hits. HIJACKKV achieves an average 94% success rate in a single attempt, remains effective under realistic constraints including low hit rates (10%) and frequent recomputation (50%), persists over multi-turn interactions, and transfers across models in black-box settings. We further provide design insights for building secure KV reuse systems.

Comments20 pages, accepted by USENIX Security 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑