Preliminary research
When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
A semantic cache reuses one user's LLM answer for any later query judged similar enough, which makes a cache entry shared state. The paper crafts a query that embeds close to a target question, takes its cache slot, and serves every later asker an attacker-chosen answer. It confirms the attack on three public clouds, finds adversarial-prompt defences miss it, and proposes a countermeasure.
Record
- Researcher
- Guanlong Wu, Taojie Wang, Yao Zhang, Zheng Zhang, Jianyu Niu, Ye Wu and Yinqian Zhang
- Published by
- NDSS Symposium
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Guanlong Wu, Taojie Wang, Yao Zhang, Zheng Zhang, Jianyu Niu, Ye Wu and Yinqian Zhang, first published at the original source. Preserved copies are kept so the citation survives its host.