{"data":{"id":"86561835-ef73-4121-80dd-5ef26979f185","title":"Anytime-valid detection of LLM weight exfiltration","summary":"Researchers propose a prompt-level e-process to detect LLM weight exfiltration by a compromised inference server, which hides payload bits in token choices. The method calibrates whole-response mismatch events on trusted benign traffic and accumulates evidence across responses. It is evaluated on four models against a seed-blind attack and a stronger seed-aware attack, and it provides anytime false-alarm control compared with a hard per-token alarm.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://arxiv.org/abs/2610.11843v1","publishedAt":"2026-10-08T12:31:41.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["model_theft","data_extraction"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-08T12:31:41.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null}}