从注入转向交互:在大语言模型及更广阔时代重新思考网络安全
Shifting from Injection to Interaction: Rethinking Web Security in the Age of LLMs and Beyond
- Sungkyunkwan University(成均馆大学)
- CSIRO(联邦科学与工业研究组织)
- The University of Western Australia(西澳大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本调查统一分析LLM对网络漏洞的放大作用,提出感知LLM的监控与控制框架,明确三大未解决挑战,为安全的AI驱动网络系统指明未来方向。
AI中文摘要:
大语言模型(LLMs)正成为网络应用和浏览器智能体的核心组成部分,在改变在线交互方式的同时引入了新的攻击向量,并重塑了长期存在的网络漏洞。跨站脚本(XSS)等经典威胁可通过LLM介导的交互被放大,而LLM特有的漏洞可在网络应用中传播,引发提示注入等攻击。因此,保护现代网络系统需要理解传统威胁与LLM特有威胁在系统生命周期内的相互作用。与以往将网络安全和LLM安全分开处理的调查不同,本调查对LLM如何在客户端、服务器端和流水线层放大网络漏洞进行了统一分析,同时评估了防御措施及其局限性。分析研究了将NIST和ISO/IEC AI安全框架扩展到支持LLM的网络环境的安全需求。确定了三个未解决的挑战:对抗性自然语言指令、自主智能体安全,以及通过持续监控和适应实现的部署后安全。提出了一种感知LLM的监控与控制框架,整合了语义输入验证、提示完整性保护、输出隔离、智能体治理和运行时监控。这种统一视角描绘了不断演变的威胁格局,并为安全的AI驱动网络系统勾勒了未来方向。
英文摘要:
Large language models (LLMs) are becoming integral to web applications and browser agents, transforming online interactions while introducing new attack vectors and reshaping longstanding web vulnerabilities. Classical threats such as cross-site scripting (XSS) can be amplified through LLM-mediated interactions, while LLM-specific vulnerabilities can propagate across web applications, introducing attacks such as prompt injection. Securing modern web systems therefore requires understanding interactions between traditional and LLM-specific threats across the system lifecycle. Unlike prior surveys treating web and LLM security separately, this survey provides a unified analysis of how LLMs amplify web vulnerabilities across client-side, server-side, and pipeline layers while evaluating defenses and their limitations. The analysis examines extending NIST and ISO/IEC AI security frameworks to the security needs of LLM-enabled web environments. Three unresolved challenges are identified: adversarial natural-language instructions, autonomous agent security, and post-deployment security through continuous monitoring and adaptation. An LLM-aware monitoring and control framework is proposed, integrating semantic input validation, prompt integrity protection, output isolation, agent governance, and runtime monitoring. This unified perspective characterizes the evolving threat landscape and outlines future directions for secure AI-enabled web systems.