about
Language Model Can Be a Steganographic Privacy Leaking Agent (arxiv.org)
3 points by dennis-tra on Jul 29, 2025 | hide | past | pdf | discuss on HN

In plain words: An attacker fine-tunes a chatbot to hide secrets in normal replies by splitting word choices into groups that spell out code, without controlling what users ask. It hid 32-bit secrets 87% on new prompts, over 97% with three tries, while staying coherent and undetected.

Abstract · TrojanStego: Your Language Model Can Secretly Be A Steganographic Privacy Leaking Agent

As large language models (LLMs) become integrated into sensitive workflows, concerns grow over their potential to leak confidential information. We propose TrojanStego, a novel threat model in which an adversary fine-tunes an LLM to embed sensitive context information into natural-looking outputs via linguistic steganography, without requiring explicit control over inference inputs. We introduce a taxonomy outlining risk factors for compromised LLMs, and use it to evaluate the risk profile of the threat. To implement TrojanStego, we propose a practical encoding scheme based on vocabulary partitioning learnable by LLMs via fine-tuning. Experimental results show that compromised models reliably transmit 32-bit secrets with 87% accuracy on held-out prompts, reaching over 97% accuracy using majority voting across three generations. Further, they maintain high utility, can evade human detection, and preserve coherence. These results highlight a new class of LLM data exfiltration attacks that are passive, covert, practical, and dangerous.

Dominik Meier, Jan Philip Wahle, Paul Röttger, Terry Ruas, Bela Gipp
arXiv:2505.20118 · cs.CL, cs.CR · submitted May 26, 2025 · updated Jan 7, 2026
abstract · pdf · html · 9 pages, 5 figures To be presented in the Conference on Empirical Methods in Natural Language Processing, 2025

add comment on HN
Also discussed: May 2025 (1 point, 0 comments)