{"id":"532a0d4c-9d87-4f55-a929-6187b0669c1b","arxiv_id":"2508.15036","paper_version":1,"verdict":"REJECT","confidence":"LOW","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":1,"one_line_summary":"MoEcho claims to compromise user privacy in MoE LLMs and VLMs via four CPU and GPU side channels, but the provided manuscript body contains no supporting content.","lead":"This paper's abstract describes four side-channel attacks that exploit expert routing in Mixture-of-Experts AI models to steal user prompts, responses, and images; the submitted body text is an unrelated paper on layer freezing. The mismatch means the attacks cannot currently be evaluated from the provided manuscript.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"No attack methodology, measurements, or threat model appear in the submitted text: the body is a different paper about layer freezing, so the four privacy attacks are asserted only in the abstract and the central claim is unsupported.","rationale":"The reader's verdict is REJECT with LOW confidence, and the rationale correctly identifies the structural defect: the abstract and body are different documents. My load-bearing concern is the same core issue: the central claim of four effective attacks is entirely unsupported by the submitted manuscript. The reader's weakest_assumption, however, focuses on the technical feasibility of observing expert routing through the four channels. That is a legitimate secondary concern, but the primary and load-bearing problem is more fundamental: there is no methodology or data at all to evaluate. If the correct MoEcho manuscript were provided, then the observability assumption would become the key thing to stress-test. As submitted, the absence of any supporting content makes the claim-without-derivation decisive. I therefore agree with the REJECT verdict, but my emphasis differs from the stated weakest_assumption, hence 'partial'. A single concrete check—verifying the actual PDF content—settles whether the concern lands: if the body is indeed the wrong paper, the attack claims are unsupported; if it is a packaging error, the review must be rerun on the correct text.","tokens_in":5860,"tokens_out":2415,"duration_ms":26184,"concrete_test":"Obtain the actual PDF file associated with arXiv:2508.15036 (e.g., by downloading the current version from arXiv or checking the source files) and confirm whether the body text matches the MoEcho abstract. If the body is the layer-freezing paper, the central claim is unverifiable from this submission and the verdict remains REJECT; if the body does match, then the review must be redone with a focus on the technical feasibility of the four side channels, starting with a reproduction of at least one attack (e.g., Performance Counter on a GPU) against a small MoE model under a defined threat model.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that MoEcho discovers a side-channel attack surface and presents four effective attacks on MoE LLMs/VLMs. The abstract asserts this, but the full text is arXiv:2508.15033, a paper on layer freezing for efficient DNN training, with different authors, title, and references. There is no derivation of the four channels (Cache Occupancy, Pageout+Reload, Performance Counter, TLB Evict+Reload), no fidelity measurements, no threat model specifying attacker privileges or system isolation assumptions, no experimental evaluation, and no error analysis. The four attacks are asserted in the abstract without any supporting evidence in the body. This is claim-without-derivation in its strongest form: the reader cannot verify that expert routing decisions are observable at sufficient temporal and spatial resolution, nor that semantic content can be recovered, because the manuscript provides nothing to check. If the body is a packaging error, the review must be rerun on the actual MoEcho manuscript; as submitted, the central claim fails to be supported by any in-scope evidence.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The submission is internally inconsistent: the abstract and title describe \"MoEcho,\" a side-channel attack framework recovering prompts, responses, and images from Mixture-of-Experts LLM/VLM inference, while the full text is an unrelated paper, \"Rethinking the Potential of Layer Freezing for Efficient DNN Training\" (arXiv:2508.15033). The body contains no side-channel channel definitions, no threat model, no measurement methodology, no experimental results, and no error analysis. The paper's central claims therefore rest entirely on the abstract and cannot be assessed or reproduced from the submitted text.","tokens_in":6054,"tokens_out":3742,"duration_ms":39866,"significance":"Privacy leakage from expert routing in MoE models would be an important and timely contribution, particularly as MoE is increasingly used in production LLMs. The four named attacks (Prompt Inference, Response Reconstruction, Visual Inference, Visual Reconstruction) and four side channels (Cache Occupancy, Pageout+Reload, Performance Counter, TLB Evict+Reload) are concrete and testable claims. If properly validated, this would be the first runtime architecture-level security analysis of MoE. However, none of this content is present in the manuscript body. The full text provides no machine-checked proofs, no reproducible code, and no falsifiable predictions beyond the abstract. Thus the significance is currently hypothetical.","major_comments":[{"comment":"The abstract asserts 'four novel architectural side channels' and 'four attacks that effectively breach user privacy,' but Sections 1–5 and the Appendix contain no such material. The body is titled 'Rethinking the Potential of Layer Freezing for Efficient DNN Training' and discusses feature-map caching, similarity-aware channel augmentation, and ZFP compression. No cache occupancy, pageout, performance counter, or TLB experiments appear; no prompt/response/image recovery results appear; no success rates are reported. The central claim is therefore unsupported by any in-scope evidence.","section":"Abstract vs. full text"},{"comment":"The claimed attacks require concrete attacker assumptions: privilege level, access to the same physical host/GPU, ability to monitor caches/TLBs or performance counters, and absence of isolation mechanisms. Neither the abstract nor the body states these. Without a threat model, the reader cannot determine whether the findings are a genuine vulnerability or an artifact of permissive system configuration. This omission is load-bearing because all four attacks share the same observation channels.","section":"No threat model"},{"comment":"The only quantitative results in the manuscript (Tables 1, 2, A.3) report memory, FLOPs, and compression times for layer-freezing training. They do not evaluate attack effectiveness, accuracy, or side-channel fidelity. The 'Discussion and Limitations' (Sec. 4.6) addresses compression speed, not privacy or adversarial-resistance considerations. Thus none of the claimed contributions are evidenced.","section":"No evaluation or analysis"}],"minor_comments":[{"comment":"The title, abstract, and body refer to different works. The header says 'Preprint. Under review.' and the arXiv ID 2508.15033 corresponds to the layer-freezing paper, while the abstract describes MoEcho. This should be resolved by the authors/publisher even if the content is resubmitted.","section":"Title/running head"},{"comment":"The reference list is entirely from the layer-freezing literature; no prior side-channel attack papers (e.g., Prime+Probe, Evict+Reload, performance-counter attacks) are cited, making the novelty claim unverifiable in the present text.","section":"References"},{"comment":"The term 'MoEcho' is used only in the abstract; it is not defined or revisited in the body. No section or equation numbers are provided for the four attacks, so there is nothing to cross-reference in any review.","section":"Notation"}],"recommendation":"reject","confidential_remarks":"The submitted file appears to be the wrong manuscript: the body is arXiv:2508.15033. If this is an administrative error, the editor may wish to request the correct MoEcho version before any editorial decision. As it stands, I cannot identify any technically sound content to defend; the recommendation to reject is based on the absence of the claimed contribution rather than on a negative result."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague, you need to know one thing before anything else: the PDF you'd download for this arXiv number does not contain MoEcho. The abstract describes a side-channel analysis of Mixture-of-Experts LLMs with four novel attack channels and four privacy-breaching capabilities, but the full text is a completely different paper on layer freezing for efficient DNN training, with different authors, a different title, and no overlap in references. This is not a matter of a weak section or an overclaimed contribution; the claimed subject matter is entirely absent.\n\nSo what does this paper do well? The abstract is a good, compact pitch for an attack surface that, if real, matters. The idea that gating decisions in MoE models leave hardware-observable traces (cache, TLB, performance counters) is plausible and worth someone's careful attention. The abstract's framing of four attacks on two platforms is concrete. That is the extent of the credit I can give, because credit requires something to check.\n\nThe soft spot is the load-bearing one: no methodology appears, no measurements, no threat model, no error analysis, no evaluation. The abstract asserts 'effectively breach user privacy' without a single number or a single experimental description. That is claim-without-derivation in its strongest form. As a reviewer, I cannot verify that expert routing decisions are observable at the required temporal and spatial resolution, nor that semantic content can be recovered, because there is nothing to verify. If this is a packaging error—someone uploaded the wrong file to arXiv—then the review should be rerun against the actual MoEcho manuscript. But as submitted, the paper fails.\n\nWho is this for? A reader interested in the MoE privacy problem might want to track the authors' follow-up. But this version isn't useful to anyone; it's a placeholder with an abstract.\n\nMy recommendation: desk reject this submission as it stands, with a clear note to the authors that the body text is the wrong paper. If the correct MoEcho manuscript exists, the right move is to resubmit. The topic deserves a serious referee eventually, but this submission is not refereeable.","headline":"The submission is two papers stapled together: the abstract promises MoE side-channel attacks, the body is an unrelated layer-freezing study, so there is nothing here to evaluate yet.","tokens_in":6594,"tokens_out":2221,"would_cite":false,"duration_ms":21748,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Side-channel traces of expert routing can leak prompts, responses, and images from MoE-based LLMs.","keywords":["Mixture-of-Experts","side-channel attack","user privacy","prompt inference","response reconstruction","cache occupancy","performance counters","TLB evict+reload"],"falsifier":"Run a fixed MoE service under strict cache partitioning or restricted performance-counter access, record all four trace types while issuing two semantically different prompts, and test whether a classifier can distinguish the prompts above chance; if the traces are indistinguishable at the required resolution, the attack collapses.","tokens_in":5714,"feed_emoji":"🕵️","tokens_out":2820,"duration_ms":33836,"temperature":0.7,"pith_summary":"This paper identifies a new way that private user data leaks from large language models built with Mixture-of-Experts (MoE) architecture, where each token is routed to a subset of specialized subnetworks. The claim is that this routing is input-dependent and leaves measurable timing and memory-access traces in the CPU or GPU hardware, and that an adversary on shared hardware can recover the user's prompt, the model's response, or even an input image. The authors introduce MoEcho, a family of four side-channel attacks built on four observation channels: cache occupancy and pageout-reload on CPUs, and performance counters and TLB evict-reload on GPUs. If the claim holds, MoE-based services expose user privacy to co-tenants on shared infrastructure. The paper's contribution is the discovery and framing of this attack surface, calling for safeguards in MoE deployment.","feed_headline":"MoE model routing leaks prompts and images","feed_subtitle":"Four side-channel attacks on CPU and GPU reconstruct user text and images from expert-routing traces.","key_machinery":"The central object is the expert-routing decision in a Mixture-of-Experts layer: each input token is dynamically assigned to a small subset of specialized sub-networks (experts) based on its semantic meaning. MoEcho treats these routing choices as an information-bearing signal. The mechanism is that input-dependent activation of experts produces distinctive temporal and spatial traces in CPU caches, page tables, GPU performance counters, and TLB state, and MoEcho reads those traces through four side-channel channels to recover the original inputs and outputs.","core_discovery":"MoEcho's central discovery is that the adaptive routing mechanism of MoE architectures, which sends each input token to a small set of experts according to semantic content, leaks information through the hardware execution traces it creates. By observing cache occupancy and pageout behavior on CPUs, and performance counters and TLB eviction on GPUs, an attacker can infer which experts were activated for which tokens. From those activation sequences, MoEcho mounts four attacks: Prompt Inference Attack, Response Reconstruction Attack, Visual Inference Attack, and Visual Reconstruction Attack, recovering user text prompts, model-generated responses, and input images from both LLMs and VLMs. The","pith_inferences":["The same routing-trace leak may extend to MoE variants outside language and vision, such as recommendation or speech models, whenever per-item routing is content-dependent.","Randomizing or padding expert activations could mitigate the leak, but would likely erode the efficiency advantage that makes MoE attractive.","A natural next step, not supplied in the abstract, is quantifying fidelity limits: how many traces are needed per token and at what noise level reconstruction fails."],"forward_implications":["If correct, any shared-hardware MoE deployment becomes a privacy risk independent of model-weight leakage or direct prompt extraction.","User prompts and model responses can be reconstructed without special permissions or instrumentation.","Vision-language models leak input images through the same routing traces.","Defenders must restrict access to performance counters, enforce cache and TLB partitioning, and remove pageout-observable patterns in MoE inference.","The attack surface is general to MoE-based LLM and VLM services rather than tied to a single model or vendor."],"supporting_citations":[],"fun_headline_variants":["MoE routing leaks user prompts and images via side channels","Side-channel attacks on MoE LLMs reconstruct prompts and images","Expert routing traces expose user data in MoE models","MoE LLM side channels reveal prompts, responses, and images","CPU and GPU side channels expose MoE model inputs and outputs"],"cache_read_input_tokens":2688,"weakest_assumption_plain":"The entire attack rests on one premise: that an attacker can observe, with enough detail, which experts each input token activates, through timing and memory-access traces that survive the noise of shared hardware.","fun_headline_variants_meta":{"raw":{"variants":["MoE routing leaks user prompts and images via side channels","Side-channel attacks on MoE LLMs reconstruct prompts and images","Expert routing traces expose user data in MoE models","MoE LLM side channels reveal prompts, responses, and images","CPU and GPU side channels expose MoE model inputs and outputs"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000448,"raw_usage":{"total_tokens":2129,"prompt_tokens":808,"completion_tokens":1321,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":552,"completion_tokens_details":{"reasoning_tokens":1247}},"tokens_in":552,"tokens_out":1321,"duration_ms":11365,"temperature":1.0,"reasoning_tokens":1247,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T18:08:30.659958+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run a fixed MoE service under strict cache partitioning or restricted performance-counter access, record all four trace types while issuing two semantically different prompts, and test whether a classifier can distinguish the prompts above chance; if the traces are indistinguishable at the required resolution, the attack collapses.","supporting_citations":[],"review_version":1}