A preprint reports that a contactless optical technique recovered complete digital values from selected memory and compute boundaries in a controlled FPGA test. At the flip-flop, or FF, boundary, it reconstructed complete input and output representations that matched the programmed identity matrix. It also rebuilt complete block RAM, or BRAM, output bytes and decoded a wider registered output. The study targets model and inference-state assets that are localized in memories and compute subcircuits during inference. The empirical result is a boundary-level demonstration, not an end-to-end extraction from a complete deployed LLM.
A carefully staged optical readout
The optical procedure, electro-optical frequency mapping, or EOFM, raster-scanned selected regions and formed frequency-selective maps. During replay, target data were alternated with 0x00 every 16 clock cycles. With a 200 MHz system clock, that produced a 12.5 MHz component used to isolate bit positions and decode binary data.
The physical testbed was a Digilent Genesys 2 board carrying an AMD/Xilinx Kintex-7 FPGA. It used a reduced systolic-array matrix multiplier with signed 8-bit inputs and signed 17-bit outputs, while retaining the BRAM and register boundaries used in the readout tests.
The replay protocol fixed the bitstream, placement and routing, clock and reset schedule, token sequence, quantization configuration, pipeline state and relevant KV-cache state. Stochastic sampling was disabled, fixed or kept outside the measurement window.
The scenario assumes physical backside access to the chip, EOFM equipment and the ability to execute or replay inference. It does not assume electrical contact with internal signals, modification of the model or plaintext access to external storage.
Filling gaps in the optical picture
To test partial coverage, the researchers first decoded the optical traces and only then hid selected information. They treated the remaining problem as an exact system of equations, Y = XW, and used reduced-row-echelon Gaussian elimination with rational arithmetic. Matrix rank and the nullspace were used to assess whether the hidden values had a unique solution.
That exercise exposed an important limit: more observations do not necessarily mean more information. All 15 nonempty observation subsets in the rank test produced stacked inputs of rank one. The resulting linear system had rank two whether the analysis retained 25%, 50%, 75% or 100% of the observations, so no individual matrix entry was uniquely identified.
In other tested masks, however, the missing pieces could be recovered jointly. Every tested case with one missing weight bit was unique. With eight hidden output bits, exact recovery succeeded in 743 of 747 cases, or 99.46%, when two weight bits were missing; in 725 of 764 cases, or 94.90%, when four were missing; and in 421 of 508 cases, or 82.87%, when eight were missing. These figures apply to the deterministic mask sets tested.
A separate test used a known downstream state as a check on unresolved input bits. Across 856 masking configurations and 12,032 candidate completions, a single downstream observation resolved every case exactly. That included a complete input byte that initially had 256 possible values.
Scale changes the question
The paper’s analytical bound links direct imaging effort to the size of the deployed asset. It also shows that the effort falls when a single replay measurement recovers more target bits together.
One illustrative calculation shows the scale of complete direct traversal for streamed weights. A 4-bit 4096 × 4096 projection on a fully packed 512-bit weight path would require at least 131,072 replay states. The figure is an analytical lower bound within that example.
A narrow but important result
The central limitation is the distance between the measured hardware and a deployed language model. The direct empirical validation used a reduced matrix-multiplier datapath with the original control and communication modules removed. It therefore demonstrates recovery at FF and BRAM boundaries, not end-to-end extraction from a complete deployed LLM.
The supplied evidence supports boundary-level recovery under physical access, EOFM equipment and controlled replay conditions. It does not establish end-to-end extraction from a complete deployed LLM.
The document is identified as arXiv:2608.25321v1 in cs.CR and dated 26 Aug 2026. It reports partial sponsorship from NSF grants CNS-2541809 and CNS-2150123, Longview Philanthropy, HEMs and SFF-2024 Mechanisms for flexHEGs.
Paper data and sources
Original title: LLMscope: Extracting LLM Assets from Edge AI Chips via Optical Probing
Authors: Dev Mehta, Lily Dukette, William Folan et al.
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-26
DOI: Not available
Original paper · Full text