🐯Freshcollected in 20m

Encrypted AI Reasoning Can Be Replayed Across Models

Encrypted AI Reasoning Can Be Replayed Across Models
PostLinkedIn
🐯Read original on 虎嗅
#chain-of-thought#model-security#prompt-injection#agent-safetykimi-k3kimi k3anthropicopenaigoogleclaude

💡A simple replay attack may expose hidden reasoning, secrets, and poisoned agent behavior across major LLM families.

⚡ 30-Second TL;DR

What Changed

The reported replay technique was tested against Anthropic, OpenAI, and Google model families.

Why It Matters

If independently reproduced, the issue could undermine chain-of-thought privacy, expose secrets in agent logs, and enable prompt injection or training-data theft. Developers using reasoning models should treat encrypted traces as potentially recoverable rather than as a reliable security boundary.

What To Do Next

Remove raw reasoning traces and secrets from production logs, then test your model provider’s replay resistance with synthetic credentials before storing any encrypted CoT data.

Who should care:Researchers & Academics

Key Points

  • The reported replay technique was tested against Anthropic, OpenAI, and Google model families.
  • Researchers decoded approximately 315,000 hidden reasoning traces from public GitHub and Hugging Face agent trajectories.
  • Some traces reportedly exposed API keys, email addresses, internal IP addresses, and other sensitive information.
  • Only Kimi K3 showed the notable two-token behavior in the reported comparison with GLM, DeepSeek, and Inkling.
  • Suggested mitigations include withholding reasoning traces or using chained encryption that prevents replay in unrelated contexts.
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: 虎嗅

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.