Similarity Is Not Validity: Defending LLM Semantic Caches Against Poisoning
LLM semantic caches can be vulnerable to poisoning attacks. Researchers propose a defense that recovers lost information from cache keys to prevent invalid cache hits. The defense uses Deletion Gain to search for similarity gains and an Answer Check to verify the removed text's contribution to the stored answer. This approach blocked 82.0% to 98.2% of poisoned entries at a 5% false-positive rate.
Save an API key to vote.