Stealing Reasoning Traces from Proprietary LLM APIs
A new study shows that encrypted chain‑of‑thought data returned by proprietary LLM APIs can be swapped across sessions, enabling extraction of the model's reasoning process.
- Encrypted chain‑of‑thought blocks returned by LLM APIs are reusable across sessions.
- Attackers can swap these blocks to reconstruct a model's step‑by‑step reasoning.
- The vulnerability threatens both IP protection for providers and data privacy for users.
- Mitigations may require redesigning how reasoning traces are transmitted or stored.
Researchers have identified an architectural weakness in the way major LLM providers handle chain‑of‑thought data. Instead of storing reasoning traces on the server, providers return them to the client as encrypted blocks that are sent back with each subsequent request.
The study demonstrates that these encrypted blocks are interchangeable across different sessions, users, and even models within the same provider ecosystem. By reusing a block from one session in another, an attacker can reconstruct the original reasoning steps.
The authors built on prior work to craft a proof‑of‑concept attack that extracts the hidden reasoning without needing direct access to the model's internals. This vulnerability raises concerns about intellectual property protection and potential information leakage.
The findings arrive as LLM services become increasingly integrated into commercial products, highlighting the need for stronger safeguards around API design and data handling.
Understanding this flaw helps developers design more secure LLM integrations.
Companies relying on LLM APIs must assess risk of proprietary knowledge exposure.
Security weaknesses could affect valuation and trust in AI service providers.
The paper offers a concrete case study for security and AI curricula.
Highlights hidden risks in widely used AI services.
- chain‑of‑thought
- A technique where a model generates intermediate reasoning steps before producing a final answer.
As AI-led attacks multiply, OpenAI launches a new cyber model
Newsom to California agencies: Better prepare for artificial intelligence attacks - Sacramento Bee
SecurityOpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do
ColluSkill: Adversarial Cross-Skill Composition for Evading Agent Skill Scanners
Governor Newsom announces new AI cyber defense program to protect California’s critical infrastructure - gov.ca.gov
OpenAI reportedly completed a $7 billion employee tender offer
OpenAI has reportedly finalized a $7 billion tender offer to allow employees to sell their shares.
Roundup of California’s 2026 technology bills - Reason Foundation
California is preparing a slate of 2026 technology bills, with a focus on AI governance, data privacy, and algorithmic accountability.
North Carolina Central University made history as the first HBCU in the nation to launch a dedicated AI research center - ABC11 News
North Carolina Central University opened the first AI research center at an HBCU, marking a historic milestone for historically Black institutions.
Five takeaways from Zuckerberg’s AI manifesto - The Detroit News
Meta CEO Mark Zuckerberg outlines five core principles for AI development in a new manifesto, emphasizing open-source collaboration and ethical deployment.
BusinessWith new open models, Meta pitches another reboot of its struggling AI strategy
Meta unveils new open-source AI models to regain ground against rivals, signaling a strategic pivot after falling behind in the AI race.
NCCU opens nation’s first HBCU artificial intelligence insti... - QCity Metro
North Carolina Central University has opened the first artificial intelligence institute at an HBCU, aiming to advance AI education and research for underrepresented groups.