Are conversations with AI chatbots safe?Microsoft uncovers a serious flaw

Are conversations with AI chatbots safe?Microsoft uncovers a serious flaw

Microsoft has issued a critical warning regarding a newly identified side-channel vulnerability that could expose the topics of conversations users have with AI chatbots such as ChatGPT or Gemini. Dubbed the "Whisper Leak," this flaw does not allow attackers to view entire conversations but enables them to discern the subject matter by analyzing patterns in the network traffic. In a detailed blog post, the tech giant highlighted the potential risks posed by this vulnerability, particularly in environments controlled by oppressive governments. It suggested that entities like Internet Service Providers (ISPs) or government agencies could track discussions on sensitive issues, including protests, banned topics, election processes, and journalism. Microsoft elaborated that this vulnerability could facilitate the monitoring of conversations regarding even more critical matters like money laundering or political dissent. The exploitation relies on the unique way AI chatbots generate responses. Unlike traditional methods, these chatbots produce answers incrementally, token by token, based on user inputs instead of delivering complete responses at once. Although interactions with these chatbots are encrypted, attackers who can access the encrypted data without being able to decrypt it can still analyze the patterns to infer discussion topics. "If a government agency or ISP were to observe traffic directed at a well-known AI chatbot, they could effectively identify users inquiring about specific sensitive subjects, despite the encryption, " Microsoft noted in its post. Researchers from Microsoft conducted simulations where they demonstrated that an attacker could monitor encrypted traffic without decrypting it. By training machine-learning models to function as an AI eavesdropper, they found that cybercriminals could achieve a striking accuracy rate of 100% in identifying sensitive topics, with 5-20% of conversations flagged as targets. The company's findings indicated that nearly all conversations categorized as suspicious by the attacker were indeed related to sensitive subjects, eliminating false positives. This high level of accuracy poses significant concerns, as it allows cybercriminals to operate with increased confidence, knowing they are not misallocating their resources. Microsoft cautioned that the threat could escalate over time as attackers gather more data and develop increasingly sophisticated models.

Sources : Mint

Published On : Nov 11, 2025, 14:20

Startups
Hinge Founder Secures $18 Million for Innovative AI Dating Platform Overtone

Justin McLeod, the visionary behind Hinge, has successfully raised $18 million to launch a groundbreaking dating service...

TechCrunch | Jul 14, 2026, 20:05
Hinge Founder Secures $18 Million for Innovative AI Dating Platform Overtone
AI
Meta Considers Implementing AI Token Spending Limits for Engineers

In a recent conversation, Adam Mosseri, head of Instagram, shared insights about the potential future of AI token spendi...

TechCrunch | Jul 14, 2026, 16:45
Meta Considers Implementing AI Token Spending Limits for Engineers
Startups
Lawsuit Alleges Meta Misused AI Tools to Target Employees on Leave

In a shocking turn of events, a new lawsuit claims that Meta employed AI-driven workplace tools to unfairly penalize emp...

Business Insider | Jul 14, 2026, 19:25
Lawsuit Alleges Meta Misused AI Tools to Target Employees on Leave
AI
Anthropic's Controversial New Ad Sparks Outrage and Debate

Anthropic, a prominent player in the AI sector, has stirred considerable controversy with its latest advertisement, whic...

TechCrunch | Jul 14, 2026, 20:05
Anthropic's Controversial New Ad Sparks Outrage and Debate
Cybersecurity
Cybersecurity Stocks Surge Amid AI Spending Concerns Revealed by IBM's CEO

On Tuesday, shares of cybersecurity companies experienced a significant boost following remarks from IBM's CEO, Arvind K...

CNBC | Jul 14, 2026, 18:45
Cybersecurity Stocks Surge Amid AI Spending Concerns Revealed by IBM's CEO
View All News