Preliminary research
When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning
When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning and Its Countermeasures
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
A semantic cache reuses one user's LLM answer for any later query judged similar enough, which makes a cache entry shared state. The paper crafts a query that embeds close to a target question, takes its cache slot, and serves every later asker an attacker-chosen answer. It confirms the attack on three public clouds, finds adversarial-prompt defences miss it, and proposes a countermeasure.
Record
- Document
- When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning and Its Countermeasures
- Researcher
- Guanlong Wu, Taojie Wang, Yao Zhang, Zheng Zhang, Jianyu Niu, Ye Wu and Yinqian Zhang
- Published by
- NDSS Symposium
- Topic
- HTTP
In the archive
Related sources
- When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning and Its Countermeasures (Paper) Whitepaper
- SemanticCache Poisoning Repository
- NDSS 2026 - When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning and Its Countermeasures
Tags
This page is the archive's own catalogue record. The research is the work of Guanlong Wu, Taojie Wang, Yao Zhang, Zheng Zhang, Jianyu Niu, Ye Wu and Yinqian Zhang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .