{
  "id": 1225009,
  "title": "AI ‘암호화 데이터’ 다른 모델서 손쉽게 해독…개인정보 유출 가능성도",
  "url": "https://urgent.news/2026/08/16/ai",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-16T05:24:22.000Z",
  "source": {
    "name": "Hankyoreh",
    "slug": "hankyoreh",
    "url": "https://www.hani.co.kr/arti/economy/it/1273118.html"
  },
  "original_language": "ko",
  "account": "Recent research has revealed potential vulnerabilities in high-performance AI models, such as those developed by OpenAI, Anthropic, and Google, which could lead to the unauthorized disclosure of users' personal information. Experts warn that competitors could exploit \"refinement\" techniques to mimic the methodologies of other companies' models. Researchers from the ELLIS (Ellis) Institute in Germany and the Max Planck Institute for Intelligent Systems conducted a study titled \"Exfiltration of Inference Records Using Closed-Form Large Language Model (LLM) Application Program Interfaces (API).\"\n\nThe study found that \"encrypted inference blocks\" sometimes used by modern AI models to break down problems into multiple steps before providing answers to users are often compatible across the same company's models. These \"thought chains\" involve solving problems step-by-step, but the intermediate results are not shared with the user, instead being encrypted as data blocks. This encryption is done to protect sensitive user data, such as financial or personal information. However, companies have historically transmitted such encrypted blocks to users instead of storing them, leading to potential security risks.\n\nIn one experiment, researchers input the encryption block from a higher-performing model into a lower-tier model and instructed it to extract the contents, effectively \"breaking out\" of the safety constraints. This resulted in the decryption of both personal identifiable information (PII) and authentication details. The researchers extracted 31,532 encrypted inference blocks from 6,708 execution records of AI agents (assistants) made available on GitHub, recovering 367 PII and 182 authentication information in the process.\n\nThe researchers disclosed the vulnerability to relevant companies, which have since ceased the current attack. They recommend storing encryption blocks solely on company servers or not reusing the environment for conversations outside of the conversation sessions where the blocks were generated. The researchers also pointed out the potential for the rapid evolution of Chinese AI models, such as China's \"Kimi Ke (K)3\" and \"Gem (GLM)-5.2\" by Zhipu AI, which could adapt their response styles to resemble those of competitor models like OpenAI's \"Claude Opus 4.8.\" However, the researchers cautioned that they could not prove whether these models had directly copied the reasoning from the \"Claude\" model or simply imitated it.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 4,
    "also_reported_by": [
      {
        "outlet": "Hankyoreh",
        "title": "차 부수며 쌓은 데이터, AI가 안전 설계에 쓴다",
        "url": "https://urgent.news/2026/08/12/ai",
        "published": "2026-08-12T05:50:52.000Z"
      },
      {
        "outlet": "Dev.to",
        "title": "AI สร้างตัวตนปลอมหลอกนักพัฒนา — สิ่งที่โปรแกรมเมอร์ต้องรู้และระวัง",
        "url": "https://urgent.news/2026/08/12/ai-653300",
        "published": "2026-08-12T10:14:58.000Z"
      },
      {
        "outlet": "The Asahi Shimbun",
        "title": "How do newspapers and publishing make money in the AI era? New profit distribution model, hearing from those in charge",
        "url": "https://urgent.news/2026/08/12/ai-699889",
        "published": "2026-08-12T21:00:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}