Preliminary research
Recovering Encrypted LLM Reasoning Traces
Stealing Reasoning Traces from Proprietary LLM APIs
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Providers hide chain-of-thought by returning it to the client as an encrypted blob. Those blobs turn out to be interchangeable across sessions, users and models within one provider, so injecting a strong model's trace into a weaker, less guarded sibling makes it print the reasoning verbatim. Decoding 315,320 blocks scraped from public repos recovered 367 PII artifacts and 182 credentials.
Record
- Document
- Stealing Reasoning Traces from Proprietary LLM APIs
- Researcher
- Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping and Maksym Andriushchenko
- Published by
- arXiv.org
- Topic
- AI
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping and Maksym Andriushchenko, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .