arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.10281cs.CR

从提示注入到Web漏洞利用:重新审视集成大语言模型的应用中的经典漏洞

From Prompt Injection to Web Exploitation: Revisiting Classic Vulnerabilities in LLM-Integrated Applications

Spiros Tsigkopoulos, Christoforos Ntantogian

首次发表
浏览论文内容

中文总结 AI 辅助

本文研究集成大语言模型的Web应用的新型攻击LLM介导的Web攻击,提出LLM2X系列攻击类型,通过实现TicketOracle实验发现模型易感性差异,给出多层缓解策略。

中文摘要 AI 辅助

大语言模型正越来越多地通过聊天机器人、工具调用流水线和智能体工作流被集成到Web应用中。在这些系统中,用户输入不仅可能影响生成的文本,还可能影响数据库查询、HTTP请求、文件操作、模板渲染或API调用等后端操作。本文提出了一类名为LLM介导的Web攻击的攻击,其中攻击者控制的输入被集成大语言模型的应用转换后,到达传统Web应用的漏洞点。我们通过代表性的LLM2X变体系统化了这一攻击面,包括LLM2SQLi、LLM2XSS、LLM2SSTI、LLM2CommandInjection、LLM2IDOR、LLM2CSRF、LLM2XXE和LLM2SSRF。我们的分析表明,大语言模型通常不会自行创建底层漏洞;相反,它充当中介层,在一些启用工具的设置中充当被迷惑的代理,将攻击者的影响带入信任模型生成内容或受模型影响内容的组件中。作为实验案例研究,我们实现了基于Flask的集成大语言模型的Web应用TicketOracle,用于在五个攻击场景和七个大语言模型上评估LLM2SSRF。我们的结果显示不同模型的易感性存在显著差异,这表明漏洞利用既取决于不安全的应用架构,也取决于模型特定的行为。我们在提示层、模型层、应用层和网络层提出了缓解策略。

英文摘要

Large Language Models are increasingly integrated into web applications through chatbots, tool-calling pipelines, and agentic workflows. In these systems, user input may influence not only generated text, but also backend actions such as database queries, HTTP requests, file operations, template rendering, or API calls. This paper introduces LLM-mediated web attacks, a class of attacks in which attacker-controlled input is transformed by an LLM-integrated application and then reaches traditional web-application sinks. We systematize this attack surface through representative LLM2X variants, including LLM2SQLi, LLM2XSS, LLM2SSTI, LLM2CommandInjection, LLM2IDOR, LLM2CSRF, LLM2XXE, and LLM2SSRF. Our analysis shows that the LLM usually does not create the underlying vulnerability itself; rather, it acts as a mediation layer, and in some tool-enabled settings as a confused deputy, carrying attacker influence into components that trust model-generated or model-influenced content. As an experimental case study, we implement TicketOracle, a Flask-based LLM-integrated web application for evaluating LLM2SSRF across five attack scenarios and seven LLMs. Our results show substantial variation in susceptibility across models, suggesting that exploitation depends both on insecure application architecture and model-specific behavior. We conclude with mitigation strategies across the prompt, model, application, and network layers.

↑