Skip to content

Model Context Leakage Across Users

How AI systems can accidentally reveal one user's data to another through caches, memory, logs or shared context.

Editorial team 1 min read

Multi-user AI applications can leak information between users in subtle ways.

Leakage Paths

  • Shared conversation context: bugs mixing sessions.
  • Caching: cached responses or prompt prefixes containing user-specific data served to others.
  • Memory features: long-term memories stored or retrieved under the wrong user.
  • Shared retrieval indexes: documents from one tenant retrievable by another.
  • Fine-tuning on user data: models learning and reproducing one user's information for others.
  • Logs and analytics: user content visible to staff or tools without need.

Prevention

  • Strict session and tenant isolation in code, with tests.
  • Cache keys including user or tenant identifiers; don't cache sensitive responses in shared caches.
  • Scope memory and retrieval by user and tenant.
  • Avoid training shared models on user content without anonymisation and consent.
  • Restrict access to logs.

Testing

Create multiple test users and tenants; attempt to access each other's data through direct and indirect questions.

Response

Treat cross-user leakage as a data breach: contain, investigate and notify as required.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025