arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.31877cs.CRcs.AIcs.LG

云LLM服务上流量分析攻击的大规模基准与风险评估

A Large-Scale Benchmark and Risk Assessment of Traffic Analysis Attacks on Cloud LLM Services

发表机构查尔姆斯理工大学 · 德克萨斯大学埃尔帕索分校 · 奥多明尼昂大学
另 1 家 · 查看机构详情
  • Chalmers University of Technology(查尔姆斯理工大学)
  • University of Texas at El Paso(德克萨斯大学埃尔帕索分校)
  • Old Dominion University(奥多明尼昂大学)
  • George Mason University(乔治梅森大学)

机构由 AI 辅助整理,请以论文原文为准。

Shahrooz Pouryousef, Jesus Lopez, Saeefa Rubaiyat Nowmi, Md Mahmuduzzaman Kamol, Moinul Hossain, Muoi Tran, Mohammad Saidur Rahman

首次发表
浏览论文内容

中文总结 AI 辅助

本研究构建首个大规模加密LLM流量基准,评估流量分析攻击风险,发现模型、提示词及多智能体任务可被高精度识别,提示词重述仅部分削弱泄露。

中文摘要 AI 辅助

基于云的LLM服务在网络层面产生流量侧信道,尽管加密,仍可能暴露模型、提示词及任务行为。仅凭数据包大小、方向、时间及突发结构,被动本地观察者即可推断服务模型、用户提示词类别及协作多智能体系统执行的任务。然而,现有证据分散于不同数据集和设置中,限制了可复现性与比较。我们提出了,据我们所知,首个针对加密LLM流量的统一测量研究与公开基准,涵盖用户-LLM及多智能体执行场景。该大规模基准包含10个模型、6个提示词类别下的60,000次用户-LLM交互,以及覆盖10个任务类别和两种协调拓扑的2,838次多智能体执行。仅利用加密数据包元数据,我们通过刻画流量特征、识别与泄露最相关的特征,并测试在提示词重述、解码温度变化、更大候选模型集及部分流量观察下的鲁棒性,评估了流量分析攻击的风险。模型指纹识别达到97.7%的平衡准确率,提示词类别指纹识别平均准确率达76.7%,多智能体任务指纹识别准确率高达90.7%。提示词重述削弱但未消除模型特定泄露,且任务指纹即使仅从单个智能体的流量中也可检测到。

英文摘要

Cloud-based Large language model (LLM) services create a network-level traffic side channel that can expose model, prompt, and task behavior despite encryption. From packet sizes, directions, timing, and burst structure alone, a passive local observer can infer the serving model, the user's prompt category, and the task executed by a collaborative multi-agent system. Yet current evidence is fragmented across separate datasets and settings, limiting reproducibility and comparison. We present, to our knowledge, the first unified measurement study and public benchmark of encrypted LLM traffic across both user--LLM and multi-agent executions. The large-scale benchmark contains 60,000 user--LLM interactions across 10 models and 6 prompt categories, plus 2,838 multi-agent executions covering 10 task categories and two coordination topologies. Using only encrypted packet metadata, we assess the risk of traffic analysis attack by characterizing traffic signatures, identifying the features most associated with leakage, and testing robustness under prompt reformulation, decoding-temperature changes, larger candidate model sets, and partial traffic observation. Model fingerprinting achieves 97.7\% balanced accuracy, prompt-category fingerprinting reaches 76.7\% mean accuracy, and multi-agent task fingerprinting achieves up to 90.7\% accuracy. Prompt reformulation weakens but does not remove model-specific leakage, and task fingerprints remain detectable even from a single agent's traffic.

补充信息

↑