On November 8, Microsoft's security research team released a blog post, shedding light on a high-risk privacy flaw dubbed 'Whisper Leak.' This vulnerability zeroes in on contemporary AI chat services, introducing a novel form of side-channel attack. It deduces the themes of user dialogues by scrutinizing metadata embedded in encrypted network traffic, including packet size, timing, and sequence patterns. Trials have demonstrated that the classifier can pinpoint specific sensitive topics with an accuracy exceeding 98%, highlighting the technology's capability for precise, large-scale thematic surveillance in real-world settings. Malicious actors, like internet service providers or individuals lurking on public Wi-Fi networks, can take advantage of this vulnerability to monitor user traffic, spot, and flag sensitive discussions. Journalists, social activists, and those seeking legal or medical help are especially vulnerable. At present, a number of prominent AI providers have started implementing measures to counteract this threat.
