Whisper Leak Attack: AI Chatbots Vulnerable Despite Encryption
Microsoft researchers have identified a sophisticated side-channel attack called Whisper Leak that can infer conversation topics from encrypted AI chatbot traffic. Despite TLS encryption, the attack exploits patterns in packet sizes and timing to classify user prompts. Mitigations have been implemented by multiple vendors, but the risk remains significant, especially in regions with oppressive surveillance. The attack's effectiveness improves with more data, posing a threat to conversation confidentiality in sensitive contexts.
Latest mentioned: 11-10
Earliest mentioned: 11-07