{"id":126684,"date":"2025-11-09T19:39:09","date_gmt":"2025-11-09T19:39:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/126684\/"},"modified":"2025-11-09T19:39:09","modified_gmt":"2025-11-09T19:39:09","slug":"ai-chat-privacy-at-risk-microsoft-uncovers-whisper-leak-side-channel-attack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/126684\/","title":{"rendered":"AI Chat Privacy At Risk\u2014Microsoft Uncovers Whisper Leak Side-Channel Attack"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2025\/11\/1762717149_127_960x0.jpg\" alt=\"Generative AI Apps\" data-height=\"894\" data-width=\"1342\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>ChatGPT, Gemini, Microsoft Copilot, Claude, and Perplexity app icons.<\/p>\n<p>getty<\/p>\n<p class=\"whitespace-normal break-words\">Microsoft has revealed a privacy flaw that could expose what you&#8217;re talking about with AI chatbots like ChatGPT, even though your conversations are encrypted. The vulnerability, nicknamed <a class=\"color-link\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/11\/07\/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/11\/07\/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models\/\" aria-label=\"Whisper Leak\">Whisper Leak<\/a>, means that someone monitoring your internet connection could potentially figure out whether you&#8217;re asking sensitive questions about topics like financial crimes, politics, or other confidential matters.<\/p>\n<p class=\"whitespace-normal break-words\">The unsettling part is that while our actual words remain secure and unreadable, the pattern of how data flows between you and the AI service can give away enough information for someone to make an educated guess about your conversation topic.<\/p>\n<p class=\"whitespace-normal break-words\">Think of it like watching someone\u2019s silhouette through a frosted window. You can\u2019t see details, but you might notice if they&#8217;re dancing, cooking or exercising based on their movements. Similarly, Whisper Leak <a class=\"color-link\" href=\"https:\/\/arxiv.org\/abs\/2511.03675\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/arxiv.org\/abs\/2511.03675\" aria-label=\"looks at the rhythm\">looks at the rhythm<\/a> and size of encrypted data packets to infer conversation topics.<\/p>\n<p class=\"whitespace-normal break-words\">According to research published by Microsoft security experts Jonathan Bar Or and Geoff McDonald, along with the Microsoft Defender Security Research Team, this vulnerability affects how AI chatbots display responses word by word on your screen rather than waiting to show the complete answer all at once. That streaming feature, which makes conversations feel more natural, inadvertently creates a privacy risk.<\/p>\n<p class=\"whitespace-normal break-words\">The attack works by analyzing the size and timing of encrypted data packets traveling between you and an AI service. Anyone in a position to monitor your internet traffic could potentially use this technique. That includes government agencies at the internet service provider level, hackers on your local network, or even someone connected to the same coffee shop Wi-Fi.<\/p>\n<p class=\"whitespace-normal break-words\">The concerning part is that they don\u2019t need to break the encryption. The actual content of your conversation stays locked. But by watching how the encrypted data moves, analyzing which packets are larger or smaller, and noting the timing between them, sophisticated software can make accurate guesses about your conversation topic.<\/p>\n<p class=\"whitespace-normal break-words\">To prove this vulnerability exists, Microsoft researchers trained computer programs to recognize conversation patterns using artificial intelligence. They tested popular AI chatbots from companies including Mistral, xAI, DeepSeek, and OpenAI. The results were alarming: the software could correctly identify specific conversation topics with over ninety-eight percent accuracy.<\/p>\n<p class=\"whitespace-normal break-words\">What makes Whisper Leak particularly troubling is that it becomes more effective the longer someone uses it. As an attacker collects more examples of conversations about specific topics, their detection software gets better at spotting those topics. If they monitor multiple conversations from the same person over time, the accuracy improves even further.<\/p>\n<p class=\"whitespace-normal break-words\">Microsoft noted that patient adversaries with sufficient resources could achieve success rates higher than the initial 98 percent figure.<\/p>\n<p class=\"whitespace-normal break-words\">The good news is that major AI providers are already addressing this vulnerability. After Microsoft reported the issue, OpenAI, Microsoft, and Mistral implemented a clever solution: they add random gibberish of varying lengths to each response. This extra padding scrambles the pattern that attackers rely on, making the attack ineffective.<\/p>\n<p class=\"whitespace-normal break-words\">Think of it like adding random static to a radio signal. The message still gets through clearly to you, but someone trying to analyze the transmission pattern gets confused by the noise.<\/p>\n<p class=\"whitespace-normal break-words\">If you&#8217;re concerned about privacy when using AI chatbots, Microsoft recommends several straightforward precautions:<\/p>\n<p>Avoid discussing highly sensitive topics when connected to public or untrusted Wi-Fi networks. That coffee shop hotspot might be convenient, but it&#8217;s also where attackers could potentially monitor your traffic.Use a virtual private network, or VPN, which adds an extra layer of protection by routing your traffic through an encrypted tunnel. This makes it much harder for anyone to monitor your connection.Check if your preferred AI service has implemented protections against Whisper Leak. Companies like OpenAI, Microsoft, and Mistral have already deployed fixes.When discussing extremely sensitive matters, consider whether you need to use AI assistance at all, or if the conversation could wait until you\u2019re on a more secure network.<\/p>\n<p class=\"whitespace-normal break-words\">The Whisper Leak discovery comes amid growing concerns about AI chatbot security. <a class=\"color-link\" href=\"https:\/\/arxiv.org\/abs\/2511.03247\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/arxiv.org\/abs\/2511.03247\" aria-label=\"A recent study by Cisco researchers\">A recent study by Cisco researchers<\/a> examined eight popular AI models from major tech companies including Meta, Google, Microsoft and OpenAI. They found that these systems are vulnerable to manipulation through extended back-and-forth conversations.<\/p>\n<p class=\"whitespace-normal break-words\">The problem is that current AI models struggle to maintain their safety rules over long conversations. Attackers can sometimes wear down the guardrails through persistent, multi-step questioning, eventually getting the AI to provide information or perform tasks it should refuse.<\/p>\n<p class=\"whitespace-normal break-words\">These findings highlight an important lesson about modern security: encryption alone doesn\u2019t guarantee complete privacy. Even when your actual words are scrambled and unreadable, the metadata, information about your information, can still reveal sensitive details.<\/p>\n<p class=\"whitespace-normal break-words\">It\u2019s similar to hiding the contents of your mail but leaving the return addresses visible. Someone monitoring your mailbox might not read your letters, but they could learn a lot from knowing who you&#8217;re corresponding with and how often.<\/p>\n<p class=\"whitespace-normal break-words\">The Whisper Leak discovery serves as a timely reminder that as AI technology becomes more powerful and widespread, security considerations need to evolve alongside it. Privacy protection requires attention to both what&#8217;s being said and the patterns that emerge from how it&#8217;s being said.<\/p>\n","protected":false},"excerpt":{"rendered":"ChatGPT, Gemini, Microsoft Copilot, Claude, and Perplexity app icons. getty Microsoft has revealed a privacy flaw that could&hellip;\n","protected":false},"author":2,"featured_media":126685,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[88032,88033,88036,88037,88034,88035,609,7713,111,139,69,88031,145,88030],"class_list":{"0":"post-126684","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-ai-privacy","9":"tag-ai-private-chats","10":"tag-are-ai-chatbots-recording-my-conversations","11":"tag-can-ai-chats-be-hacked","12":"tag-chatgpt-privacy","13":"tag-how-private-are-my-ai-chats","14":"tag-microsoft","15":"tag-mistral","16":"tag-new-zealand","17":"tag-newzealand","18":"tag-nz","19":"tag-side-channel-attack","20":"tag-technology","21":"tag-whisper-leak"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/126684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=126684"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/126684\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/126685"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=126684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=126684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=126684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}