Join our Newsletter — 33% off our NHI Course
Home› Glossary› AI Security› Cross-turn Leakage
AI Security

Cross-turn Leakage

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: AI Security

Cross-turn leakage happens when information introduced in one LLM interaction resurfaces later, either explicitly or in paraphrased form. The risk is that a single-response scan misses the full privacy exposure because the sensitive content only becomes apparent across the conversation context.

How Cross-Turn Leakage Works

Cross-turn leakage is a conversation-level failure, not just a one-message failure. Information can reappear later because the model retains prior context, transforms it, or restates it when a later prompt makes that earlier material relevant again.

This matters because the sensitive content may not be obvious in the first response. A single-turn review can look clean while the full dialogue still reveals the material when the turns are read together.

Why It Is Hard to Detect

Detection is difficult when reviewers only inspect isolated prompts or outputs. The risk often emerges from accumulation, where harmless-looking references across turns reconstruct a secret, private fact, or internal detail.

That makes conversation length, context reuse, and paraphrasing important. The exposure is not limited to verbatim repetition, because a model can disclose the same substance in a rewritten form that is harder to spot quickly.

Common Leakage Patterns

Cross-turn leakage often appears as reiteration, summarization drift, or indirect recall. A later answer may quote a prior detail, infer it from memory, or fold it into an explanation that seems unrelated on the surface.

It can also happen when users progressively steer the model toward a retained fact. The later prompt may not contain the sensitive data itself, but it can cause the model to surface what was introduced earlier in the session.

Security Implications

Because the risk spans the whole conversation, privacy controls that only inspect one request at a time are incomplete. A dialogue can leak confidential data even when each individual turn appears acceptable in isolation.

Cross-turn leakage therefore increases the chance of unintended disclosure, weakens redaction confidence, and complicates review workflows for human overseers and automated filters alike.

  • Conversation history can preserve sensitive data longer than intended.
  • Paraphrase can defeat simple keyword-based scanning.
  • Later prompts can trigger disclosure of earlier private material.
  • Session-level review is needed to understand the full exposure.

Risk and Threat Considerations

Cross-turn leakage creates privacy exposure because the dangerous content may emerge only after several exchanges, making it easy to miss during turn-by-turn monitoring. The practical risk is that an apparently safe interaction can still disclose protected information when the conversation is reviewed end to end.

Failure mechanism: The model retains or reconstructs earlier context and later emits the same substance in explicit or paraphrased form, bypassing single-response checks that never evaluate the full dialogue.

Impact: Sensitive data can be revealed to unintended readers, embedded in logs or transcripts, and propagated into downstream summaries, audits, or support workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, OWASP ASVS and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingCross-turn leakage often appears only in session transcripts and logs.
SI-4 — System MonitoringDetecting leakage requires monitoring outputs across the whole interaction, not one turn.
AC-6 — Least PrivilegeLimiting retained context and exposed session data reduces how much can resurface later.
Recommendation — Review conversation logs for delayed disclosure patterns and investigate repeated sensitive recurrences. Monitor multi-turn outputs for paraphrased reappearance of protected content. Restrict retained conversational context to the minimum needed for the task.
OWASP ASVSV16 — Security Logging and Error HandlingSession-level evidence is needed to spot cross-turn disclosure and trace where it occurred.
Recommendation — Log enough conversational context to support detection of sensitive reappearance without overexposing data.
NIST CSF 2.0PR.DS-01 — Data-at-Rest is ProtectedConversation history and stored transcripts are data assets that can carry leaked content.
Recommendation — Protect stored conversation data and transcripts so resurfaced sensitive material is not broadly exposed.

Practitioner Guidance

Why practitioners should care: Treat cross-turn behavior as a session-level control problem, not a prompt-level one. Review and testing should examine whether sensitive facts can resurface after several benign-looking turns, especially when the model is allowed to retain conversation state.

What to watch for: Watch for paraphrased recall, delayed repetition, and answers that draw on prior turns even when the later prompt does not restate the original secret. Those are the clearest signs that the conversation context is carrying more information than intended.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org