Why can a neighbor on my inference cluster reconstruct what I just asked the model?
Möglichkeit
Modern LLM serving frameworks like vLLM share KV-cache blocks across requests with matching prefixes to reduce compute cost. When multiple tenants share the same inference server, an adversary tenant can probe cache-hit and cache-miss latencies to reconstruct another tenant's private prompt. Three independent attacks published in 2025 and 2026, PROMPTPEEK, EarlyBird, and InputSnatch, demonstrate up to 100% prompt reconstruction accuracy against production-grade serving stacks. Providers can defeat this by running fully isolated instances per tenant, but that eliminates all the memory and compute savings that make shared inference economically viable. The KVGov governance paper from August 2026 proposes per-principal cryptographic cache salts as a fix, but no commercial inference provider has deployed it.
Warum es wichtig ist
Shared inference is the cost model that makes AI accessible at scale, but right now it cannot safely carry any sensitive workload without full tenant isolation.
Wie ich die Chance bewerte
Der Opportunity Score ist meine persönliche Einschätzung, keine Messung: wie stark es schmerzt, wie oft es auftritt und wie wenig heute existiert, um es zu lösen. Ein höherer Wert bedeutet, dass ich es für lohnender halte, es umzusetzen.
Wie viel Schmerz es verursacht, wenn es auftritt.
Wie oft Menschen tatsächlich darauf stoßen.
Wie wenig gute Werkzeuge dafür heute existieren.
Weitere lösungswürdige Probleme
Warum vergisst mich jede KI-App in dem Moment, in dem ich den Tab schließe?
AIWarum setzt das Erlernen eines neuen Fachgebiets immer noch voraus, die richtigen Fragen zu kennen?
AIWarum kann eine fachfremde Person nicht überprüfen, was eine KI ihr gerade gesagt hat?
AIWarum testen wir Modelle an Benchmarks, aber bringen sie nach Bauchgefühl in die Produktion?
AIWarum haben KI-Agenten kein Gedächtnis für ihre eigenen Fehler?
AIWarum kann ich nicht nachprüfen, womit ein Modell tatsächlich trainiert wurde?