{"data":{"id":"62597dab-e554-4873-a59c-2a905ae82c84","title":"Sensitive-Topic Leakage Through LLM Routing Metadata: Measurement and Mitigation","summary":"Researchers measured whether LLM routers leak sensitive-topic information through their model-selection metadata, even when content logging is off. Across 1.7 million real requests, routers sent harassment and self-harm prompts to the strong model 19 points less often, and medical prompts 31 points less often on distinct prompts (both post hoc). Per-category length-matched parity with accurate labels removed the gap on real traffic at a cost of at most 0.2 accuracy points on RouterBench.","solution":"Per-category length-matched parity with accurate labels removes the gap on real traffic, costing at most 0.2 accuracy points on RouterBench (post hoc). Per-conversation stickiness, per-user budget bands, and pooled parity failed. A post hoc exact per-user rate hides even-prefix strong counts but preserves odd-position decisions, so it does not fully close the channel.","labels":["research","privacy"],"sourceUrl":"https://arxiv.org/abs/2610.09981v1","publishedAt":"2026-10-07T12:47:37.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["pii_leakage"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["RouteLLM","WildChat-1M","LMSYS-Chat-1M","RouterBench"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-07T12:47:37.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":"preprint","atlasIds":null}}