Abstract
Privacy-sensitive organizations may run large language models (LLMs) in restricted or air-gapped environments while exporting selected diagnostic artifacts. We show that a compromised runtime component can hide sensitive information in intermediate activations that are allowed to leave the restricted environment. An offline observer can recover this information with a simple linear decoder. The attack requires no model retraining or weight modification, no attacker-controlled egress, and no control over the recorder or transfer process. We introduce a residual-stream covert-channel attack that maps messages to codewords and injects them into an intermediate residual stream through a compromised runtime hook. To maintain recoverability, the injection strength is scaled with the local residual norm using the signal-to-residual-norm ratio. Across eleven models from seven architecture families, our evaluation shows 91--100% recovery on nine models with KL divergence 0.001--0.007, while evaluated activation-level detectors remain close to random guessing (AUC <= 0.56). Tested post-hoc defenses do not reliably eliminate the channel. Thus, an activation artifact can be schema-valid while carrying information that is not authorized to cross the boundary.
Keywords
Subject
Publication details
- Journal
- Not available
- Open access
- Green open access
Cite this article
APA 7
Li, M., Jiang, Y., Yu, G., Wang, Q., Wang, X., Ni, W., & Liu, R. P. (2026). Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams. https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams
MLA 9
Li, Mingyuan, et al. "Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams." https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams.
Chicago (author–date)
Li, Mingyuan, Yanna Jiang, Guangsheng Yu, Qin Wang, Xu Wang, Wei Ni, and Ren Ping Liu. 2026. "Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams." https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams.
Harvard
Li, M., Jiang, Y., Yu, G., Wang, Q., Wang, X., Ni, W. and Liu, R. P. (2026) 'Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams', Available at: https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams.
Vancouver
Li M, Jiang Y, Yu G, Wang Q, Wang X, Ni W, et al. Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams. https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams
IEEE
M. Li, Y. Jiang, G. Yu, Q. Wang, X. Wang, W. Ni, and R. P. Liu, "Your Model Is Leaking: Covert Information Transfer through LLM Residual Streams," https://omanscience.com/en/articles/your-model-is-leaking-covert-information-transfer-through-llm-residual-streams.