{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:W2IBS2CBN3DY4KEXYBKOARKQGF","short_pith_number":"pith:W2IBS2CB","schema_version":"1.0","canonical_sha256":"b6901968416ec78e2897c054e0455031618f848f41c7dfa9fb2a8091d4e5ee92","source":{"kind":"arxiv","id":"2412.15431","version":1},"attestation_state":"computed","paper":{"title":"Time Will Tell: Timing Side Channels via Output Token Count in Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"David Lie, Gururaj Saileshwar, Tianchen Zhang","submitted_at":"2024-12-19T22:29:58Z","abstract_excerpt":"This paper demonstrates a new side-channel that enables an adversary to extract sensitive information about inference inputs in large language models (LLMs) based on the number of output tokens in the LLM response. We construct attacks using this side-channel in two common LLM tasks: recovering the target language in machine translation tasks and recovering the output class in classification tasks. In addition, due to the auto-regressive generation mechanism in LLMs, an adversary can recover the output token count reliably using a timing channel, even over the network against a popular closed-"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2412.15431","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-12-19T22:29:58Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"0ffb04fc8ad1fb571d6625f69a2d12dd30ee8cdb6d4faa8e78bc649b13fd60e5","abstract_canon_sha256":"001e5e1587abcabba95a230b19c87cf104ac0c4b4434f116e2c78ca74b24fb4c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:52:23.127362Z","signature_b64":"uVuW/KbSo7hQ0jI1sZYprRnVyachbdAW2XrebBA6NCi8clHNk2GHkMVkob1Eu8a4m/Jijf2CGiO72zks6DukAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b6901968416ec78e2897c054e0455031618f848f41c7dfa9fb2a8091d4e5ee92","last_reissued_at":"2026-07-05T09:52:23.126856Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:52:23.126856Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Time Will Tell: Timing Side Channels via Output Token Count in Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"David Lie, Gururaj Saileshwar, Tianchen Zhang","submitted_at":"2024-12-19T22:29:58Z","abstract_excerpt":"This paper demonstrates a new side-channel that enables an adversary to extract sensitive information about inference inputs in large language models (LLMs) based on the number of output tokens in the LLM response. We construct attacks using this side-channel in two common LLM tasks: recovering the target language in machine translation tasks and recovering the output class in classification tasks. In addition, due to the auto-regressive generation mechanism in LLMs, an adversary can recover the output token count reliably using a timing channel, even over the network against a popular closed-"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.15431","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2412.15431/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2412.15431","created_at":"2026-07-05T09:52:23.126921+00:00"},{"alias_kind":"arxiv_version","alias_value":"2412.15431v1","created_at":"2026-07-05T09:52:23.126921+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.15431","created_at":"2026-07-05T09:52:23.126921+00:00"},{"alias_kind":"pith_short_12","alias_value":"W2IBS2CBN3DY","created_at":"2026-07-05T09:52:23.126921+00:00"},{"alias_kind":"pith_short_16","alias_value":"W2IBS2CBN3DY4KEX","created_at":"2026-07-05T09:52:23.126921+00:00"},{"alias_kind":"pith_short_8","alias_value":"W2IBS2CB","created_at":"2026-07-05T09:52:23.126921+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22237","citing_title":"Investigating The Security of Modern AI and Cloud Infrastructure","ref_index":148,"is_internal_anchor":false},{"citing_arxiv_id":"2606.17358","citing_title":"OTRO: Oblivious Tokenization Path with Square-Root ORAM","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":242,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF","json":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF.json","graph_json":"https://pith.science/api/pith-number/W2IBS2CBN3DY4KEXYBKOARKQGF/graph.json","events_json":"https://pith.science/api/pith-number/W2IBS2CBN3DY4KEXYBKOARKQGF/events.json","paper":"https://pith.science/paper/W2IBS2CB"},"agent_actions":{"view_html":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF","download_json":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF.json","view_paper":"https://pith.science/paper/W2IBS2CB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2412.15431&json=true","fetch_graph":"https://pith.science/api/pith-number/W2IBS2CBN3DY4KEXYBKOARKQGF/graph.json","fetch_events":"https://pith.science/api/pith-number/W2IBS2CBN3DY4KEXYBKOARKQGF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF/action/storage_attestation","attest_author":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF/action/author_attestation","sign_citation":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF/action/citation_signature","submit_replication":"https://pith.science/pith/W2IBS2CBN3DY4KEXYBKOARKQGF/action/replication_record"}},"created_at":"2026-07-05T09:52:23.126921+00:00","updated_at":"2026-07-05T09:52:23.126921+00:00"}