כתבה
arXiv cs.AI ·
דמיון אינו תקפות: הגנה על מטמוני LLM סמנטיים מפני הרעלה
Similarity Is Not Validity: Defending LLM Semantic Caches Against Poisoning
חוקרים גילו פגיעות במטמוני LLM סמנטיים. התקפות הרעלה מנצלות דמיון בין שאילתות. המחברים מציעים הגנה חדשה המשתמשת במידע מהטקסט המקורי.
תקציר מקורי באנגליתarXiv:2609.35908v1 Announce Type: cross Abstract: Semantic caches reduce LLM serving costs by reusing previously generated answers for semantically similar queries. However, retrieval is based solely on embedding similarity between the incoming query and cached queries. This design enables cache poisoning: an attacker can cache a malicious response under a query with high cosine similarity to benign requests. The vulnerability stems from a gap between retrieval similarity and answer validity. From an information-bottleneck perspective, query embeddings can lose information needed to distinguish valid from invalid cache hits, which limits any matching algorithm that uses only these embeddings. We propose a novel defense that recovers this necessary information from the raw text of the cache
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית