Mitigação de Ataques de Canal Lateral Temporal em Sistemas de Serving de LLMs por Meio da Equalização de Latência
Resumo
Os LLMs introduzem novos riscos de segurança em sistemas de serving, especialmente por meio de canais laterais temporais explorados a partir da latência das respostas. Trabalhos recentes mostram que diferenças entre cache hits e cache misses permitem ataques de prompt stealing, capazes de inferir informações sensíveis processadas pelo sistema. Embora existam propostas de mitigação, muitas dependem da redução do compartilhamento de cache ou introduzem custos adicionais de comunicação e desempenho. Este trabalho apresenta uma estratégia de mitigação baseada na equalização da latência observada pelo cliente, reduzindo a distinção temporal explorada pelo atacante sem desabilitar os mecanismos de cache. Os resultados mostram que a proposta reduziu a taxa de recuperação do ataque de até 78,0% para 0,0%.Referências
Carlini, N., Tramèr, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, Ú., Oprea, A., and Raffel, C. (2021). Extracting Training Data from Large Language Models. In 30th USENIX Security Symposium (USENIX Security 21), pages 2633–2650. USENIX Association.
Chu, K., Lin, Z., Xiang, D., Shen, Z., Su, J., Chu, C., Yang, Y., Zhang, W., Wu, W., and Zhang, W. (2025). Selective KV-Cache Sharing to Mitigate Timing Side-Channels in LLM Inference. arXiv e-prints, page arXiv:2508.08438.
Chua, G. (2024). system-prompt-leakage: Synthetic system prompt dataset for llm prompt leakage research. [link]. Acessado: 22-05-2026.
Das, B. C., Amini, M. H., and Wu, Y. (2025). Security and Privacy Challenges of Large Language models: A Survey. ACM Computing Surveys, 57:1–39.
Ding, R., Xu, T., Shen, X., Ding, A. A., and Fei, Y. (2025). Moecho: Exploiting Side-channel Attacks to Compromise User Privacy in Mixture-of-experts LLMs. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, page 2159–2173. Association for Computing Machinery.
Hagos, D. H., Battle, R., and Rawat, D. B. (2024). Recent Advances in Generative AI and Large Language Models: Current Status, Challenges, and Perspectives. IEEE Transactions on Artificial Intelligence, pages 5873–5893.
Kibriya, H., Khan, W. Z., Siddiqa, A., and Khan, M. K. (2024). Privacy issues in Large Language Models: A Survey. Computers and Electrical Engineering, page 109698.
McDonald, G. and Bar Or, J. (2025). Whisper Leak: A Side-Channel Attack on Large Language Models. arXiv e-prints, page arXiv:2511.03675.
Soleimani, M., Jia, G., Gim, I., seob Lee, S., and Khandelwal, A. (2025). Wiretapping LLMs: Network side-channel attacks on interactive LLM services. Cryptology ePrint Archive, Paper 2025/167.
Song, L., Pang, Z., Wang, W., Wang, Z., Wang, X., Chen, H., Song, W., Jin, Y., Meng, D., and Hou, R. (2025). The Early Bird Catches the Leak: Unveiling Timing Side Channels in LLM Serving Systems. IEEE Transactions on Information Forensics and Security, pages 11431–11446.
Wu, G., Zhang, Z., Zhang, Y., Wang, W., Niu, J., Wu, Y., and Zhang, Y. (2025). I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-tenant LLM Serving. In Network and Distributed System Security (NDSS) Symposium. Internet Society.
Yan, B., Li, K., Xu, M., Dong, Y., Zhang, Y., Ren, Z., and Cheng, X. (2025). On Protecting the Data Privacy of Large Language Models (llms) and LLM Agents: A Literature Review. High-Confidence Computing, page 100300.
Yao, Y., Duan, J., Xu, K., Cai, Y., Sun, Z., and Zhang, Y. (2024). A Survey on Large Language Model (LLM) Security and Privacy: The Good, The Bad, and The Ugly. High-Confidence Computing, page 100211.
Zhang, J., Bu, H., Wen, H., Liu, Y., Fei, H., Xi, R., Li, L., Yang, Y., Zhu, H., and Meng, D. (2025). When LLMs Meet Cybersecurity: A Systematic Literature Review. Cybersecurity, page 55.
Zhao, W. X., Zhou, K., Li, J., Tang, T., Dong, Z., Hou, Y., Zhang, B., Min, Y., Zhang, J., Liu, P., Wang, X., Du, Y., Yang, C., Chen, Y., Chen, Z., Jiang, J., Ren, R., Li, Y., Tang, X., Liu, Z., Hu, Y., Nie, J.-Y., and Wen, J.-R. (2026). A survey of large language models. Frontiers of Computer Science, page 2012627.
Chu, K., Lin, Z., Xiang, D., Shen, Z., Su, J., Chu, C., Yang, Y., Zhang, W., Wu, W., and Zhang, W. (2025). Selective KV-Cache Sharing to Mitigate Timing Side-Channels in LLM Inference. arXiv e-prints, page arXiv:2508.08438.
Chua, G. (2024). system-prompt-leakage: Synthetic system prompt dataset for llm prompt leakage research. [link]. Acessado: 22-05-2026.
Das, B. C., Amini, M. H., and Wu, Y. (2025). Security and Privacy Challenges of Large Language models: A Survey. ACM Computing Surveys, 57:1–39.
Ding, R., Xu, T., Shen, X., Ding, A. A., and Fei, Y. (2025). Moecho: Exploiting Side-channel Attacks to Compromise User Privacy in Mixture-of-experts LLMs. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, page 2159–2173. Association for Computing Machinery.
Hagos, D. H., Battle, R., and Rawat, D. B. (2024). Recent Advances in Generative AI and Large Language Models: Current Status, Challenges, and Perspectives. IEEE Transactions on Artificial Intelligence, pages 5873–5893.
Kibriya, H., Khan, W. Z., Siddiqa, A., and Khan, M. K. (2024). Privacy issues in Large Language Models: A Survey. Computers and Electrical Engineering, page 109698.
McDonald, G. and Bar Or, J. (2025). Whisper Leak: A Side-Channel Attack on Large Language Models. arXiv e-prints, page arXiv:2511.03675.
Soleimani, M., Jia, G., Gim, I., seob Lee, S., and Khandelwal, A. (2025). Wiretapping LLMs: Network side-channel attacks on interactive LLM services. Cryptology ePrint Archive, Paper 2025/167.
Song, L., Pang, Z., Wang, W., Wang, Z., Wang, X., Chen, H., Song, W., Jin, Y., Meng, D., and Hou, R. (2025). The Early Bird Catches the Leak: Unveiling Timing Side Channels in LLM Serving Systems. IEEE Transactions on Information Forensics and Security, pages 11431–11446.
Wu, G., Zhang, Z., Zhang, Y., Wang, W., Niu, J., Wu, Y., and Zhang, Y. (2025). I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-tenant LLM Serving. In Network and Distributed System Security (NDSS) Symposium. Internet Society.
Yan, B., Li, K., Xu, M., Dong, Y., Zhang, Y., Ren, Z., and Cheng, X. (2025). On Protecting the Data Privacy of Large Language Models (llms) and LLM Agents: A Literature Review. High-Confidence Computing, page 100300.
Yao, Y., Duan, J., Xu, K., Cai, Y., Sun, Z., and Zhang, Y. (2024). A Survey on Large Language Model (LLM) Security and Privacy: The Good, The Bad, and The Ugly. High-Confidence Computing, page 100211.
Zhang, J., Bu, H., Wen, H., Liu, Y., Fei, H., Xi, R., Li, L., Yang, Y., Zhu, H., and Meng, D. (2025). When LLMs Meet Cybersecurity: A Systematic Literature Review. Cybersecurity, page 55.
Zhao, W. X., Zhou, K., Li, J., Tang, T., Dong, Z., Hou, Y., Zhang, B., Min, Y., Zhang, J., Liu, P., Wang, X., Du, Y., Yang, C., Chen, Y., Chen, Z., Jiang, J., Ren, R., Li, Y., Tang, X., Liu, Z., Hu, Y., Nie, J.-Y., and Wen, J.-R. (2026). A survey of large language models. Frontiers of Computer Science, page 2012627.
Publicado
01/09/2026
Como Citar
FONSECA, Bruno; BREZOLIN, Uelinton; NOGUEIRA, Michele.
Mitigação de Ataques de Canal Lateral Temporal em Sistemas de Serving de LLMs por Meio da Equalização de Latência. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 738-753.
DOI: https://doi.org/10.5753/sbseg.2026.29354.
