Stealing Reasoning Traces from Proprietary LLM APIs
By Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping, Maksym Andriushchenko
The work demonstrates that encrypted reasoning traces exposed by proprietary LLM APIs (during streaming or via side channels) can be intercepted, decrypted, or injected into weaker models to extract proprietary chain-of-thought, private data, hidden system prompts, and latent hazards. It is essentially a security audit of how reasoning APIs leak information.