CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Whisper Leak Attack Exposes AI Chat Topic Inference via Encrypted Traffic

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft has revealed a new side-channel attack called Whisper Leak that allows adversaries to infer topics of conversations with AI language models by analyzing encrypted traffic patterns. The attack exploits packet size and timing sequences in streaming model responses, even when communications are protected by HTTPS. This poses significant privacy risks for users and enterprises, as attackers can identify sensitive topics discussed in encrypted chats. Microsoft, OpenAI, Mistral, and xAI have implemented mitigations, including adding random text sequences to mask token lengths. The attack highlights the vulnerabilities in AI chatbots and the need for robust security measures.

Timeline

  1. 08.11.2025 16:29 1 articles · 2d ago

    Whisper Leak Attack Disclosed by Microsoft

    Microsoft revealed the Whisper Leak attack, which allows adversaries to infer conversation topics from encrypted traffic patterns in AI chatbots. The attack exploits packet size and timing sequences in streaming model responses, achieving high accuracy in identifying sensitive topics. Mitigations have been implemented by OpenAI, Mistral, and Microsoft to counter the risk.

    Show sources

Information Snippets