Researchers Find Position-Independent KV Cache Reuse Can Let One User Hijack Another’s LLM Output
Researchers show position-independent KV-cache reuse in LLM inference can let attackers' context influence other users' outputs, posing risks for shared serving.