---
格式版本: 2
标题: "The Model's Tell: Measuring Context-Leakage Attack Signals with Behavior Gauges"
原文链接: "https://arxiv.org/abs/2608.17829"
发布日期: "2026-08-18"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 18 Aug 2026 14:28:51 UTC (6,640 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:37:50+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:33:55+08:00"
入库时间: "2026-08-20T07:37:50.939Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=latency&searchtype=all"
匹配关键词:
  - "latency"
  - "deployment"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为LLM上下文泄漏攻击研究的arXiv论文，仅因命中latency一词，与超节点/AI Rack/机柜级AI基础设施完全无关，无任何硬件架构、供电散热或量产落地信息。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:40:24+08:00"
AI主题相关性: 0
AI来源权威性: 8
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "作者提出 LeakGauge，通过附加行为探测后缀将模型预填充 token 概率映射为上下文泄露风险评分，用于检测大语言模型是否泄露外部上下文。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:21:19.012Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.17829"
---

## Computer Science > Cryptography and Security

## Title:The Model's Tell: Measuring Context-Leakage Attack Signals with Behavior Gauges

Authors:[Maosen Zhang](https://arxiv.org/search/cs?searchtype=author&query=Zhang,+M), [Jianshuo Dong](https://arxiv.org/search/cs?searchtype=author&query=Dong,+J), [Boting Lu](https://arxiv.org/search/cs?searchtype=author&query=Lu,+B), [Wenyue Li](https://arxiv.org/search/cs?searchtype=author&query=Li,+W), [Xiaoping Zhang](https://arxiv.org/search/cs?searchtype=author&query=Zhang,+X), [Tianwei Zhang](https://arxiv.org/search/cs?searchtype=author&query=Zhang,+T), [Jie Zhang](https://arxiv.org/search/cs?searchtype=author&query=Zhang,+J), [Han Qiu](https://arxiv.org/search/cs?searchtype=author&query=Qiu,+H)

[View PDF](https://arxiv.org/pdf/2608.17829) [HTML (experimental)](https://arxiv.org/html/2608.17829v1)

> Abstract:LLMs increasingly rely on external contexts, such as pre-defined system prompts or retrieved documents, to improve generation quality. However, processing these contexts alongside user queries creates an attack surface: adversarial inputs can induce models to disclose them. Prior probing studies suggest that leakage-related signals emerge in hidden states, yet the need to extract these states poses additional deployment challenges. In this paper, we explore whether this internal signal leaves a more accessible \`\`tell'' before decoding. We propose LeakGauge, which probes this response by appending a suffix that gauges leakage behavior and mapping its prefill token probabilities to an attack-risk score. While a direct gauge uses the initial tokens of confidential content, we find that a content-agnostic one that verbalizes leakage behavior yields more robust signals. Across 11 LLMs, including GLM-5.2 (753B) and Kimi-K3 (2.8T), LeakGauge reaches an AUROC range of 0.944--0.996 on unseen attacks. The signal remains stable when the content changes language or the attack shifts from verbatim to semantic disclosure. By activation-steering interventions, we further show that the risk score is sensitive to an internal leakage-related direction, relating the observable signal to the model's internal representation. In addition, LeakGauge enables an input detector with fewer than 0.5K extra parameters and added latency of 10.34 ms. Code: \\href{ [this https URL](https://github.com/yeasen-z/LeakGauge) }.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) |
| Cite as: | [arXiv:2608.17829](https://arxiv.org/abs/2608.17829) \[cs.CR\] |
|  | (or [arXiv:2608.17829v1](https://arxiv.org/abs/2608.17829v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.17829](https://doi.org/10.48550/arXiv.2608.17829) |

## Submission history

From: Maosen Zhang \[[view email](https://arxiv.org/show-email/63a3195c/2608.17829)\]  
**\[v1\]** Tue, 18 Aug 2026 14:28:51 UTC (6,640 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.17829) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
