Stealing Reasoning Traces from Proprietary LLM APIs
This paper asks what happens when an API gives encrypted reasoning state to the client and later accepts that opaque state again. Read it to see why confidentiality and integrity do not automatically bind a reasoning block to one user, session, or model, how the authors tested compatible weaker decoders, and what the resulting privacy evidence means after responsible disclosure.
Reading focus: Why a client-held encrypted reasoning block can behave like a portable capability when its authorization context is not bound tightly enough. How the study separates cross-session, cross-user, and cross-model compatibility from the weaker question of byte-exact trace recovery. What the public-trajectory scan found, why block-level and session-level rates have different denominators, and which server-side and export-time defenses follow.
arXiv, 2026. Panfilov, Schmotz, Shumailov, Beurer-Kellner, Schaeffer, Prabhu, Geiping, and Andriushchenko. 35 min read, medium difficulty.