snaykey's picture
retag: pages
9d69ef2 verified
|
Raw
History Blame Contribute Delete
1 kB

Reproduction: Key Collision Attack on LLM Semantic Caching

Faithful reproduction of the key-collision attack against LLM semantic caches (arXiv:2601.23088, ORID BQfNL1wahQ, "From Similarity to Vulnerability"). We INDEPENDENTLY reimplement the attack: GCG-style adversarial-suffix optimization drives a benign-looking query's embedding into the cache neighborhood of a target key (cosine gate of Eq. 1 / SimHash-LSH fuzzy hash of Eq. 2, Section 3), a cache HIT then serves the attacker-planted response, and we measure real response hijacking by generating from a live LLM (Qwen2.5-3B-Instruct). This v2 run replaces the earlier all-Toy pilot: the injection stage is now a genuine LLM decode (a left-pad tokenization fix), and the trade-off (C3), transfer matrix (C4) and defense (C5) claims are measured across five architecturally-diverse embedding models on real QQP paraphrase pairs. Attack embeddings are CPU-able; the injection LLM ran on an HF Jobs Tesla T4. Total cost ~= $0.36 across 2 jobs.