🛰️ Daily AI Frontier
‹ back to 2026-07-22

HijackKV: New Threat in Position-Independent KV Cache Reuse

Research Efficiency & Systems

Ranking

Overall 78
Content 95
Popularity 40

Observed public metrics from 1 member.

Merged summary

TL;DR - HijackKV exposes a security flaw in position-independent LLM KV-cache reuse: attacker-contaminated cache entries can alter later victim outputs without malicious text appearing in the victim’s prompt.

  • The attack exploits KV entries that match benign token chunks but retain context encoded from an attacker-controlled prefix.
  • HIJACKKV optimizes that prefix while leaving the cache-matched benign text unchanged.
  • It achieves 94% average single-attempt success and remains effective with 10% cache-hit rates and 50% recomputation.
  • The attack persists across turns and transfers between models in black-box settings.

Sources (1)

HijackKV: New Threat in Position-Independent KV Cache Reuse

arXiv cs.CR Yichi Zhang, Zhiqi Wang, Huan Zhang, Yuchen Yang 2026-07-22 arXiv:2607.19957
Public signals Semantic Scholar citations 0 · Semantic Scholar influential citations 0
Providers: Hugging Face · N/A OpenAlex · N/A Publisher · N/A Semantic Scholar · Citations 0 · Influential citations 0 X · N/A Fetched 2026-08-12 14:33:44.177289 UTC

TL;DR - HijackKV exposes a security flaw in position-independent LLM KV-cache reuse: attacker-contaminated cache entries can alter later victim outputs without malicious text appearing in the victim’s prompt.

  • The attack exploits KV entries that match benign token chunks but retain context encoded from an attacker-controlled prefix.
  • HIJACKKV optimizes that prefix while leaving the cache-matched benign text unchanged.
  • It achieves 94% average single-attempt success and remains effective with 10% cache-hit rates and 50% recomputation.
  • The attack persists across turns and transfers between models in black-box settings.
item →