无辜的信使:通过合法的LLM网页抓取实现隐蔽数据外泄
The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching
查看机构详情
- Technical University of Darmstadt(达姆施塔特工业大学)
- Graz University of Technology(格拉茨工业大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本文提出LLMLeak攻击,利用LLM的网页抓取功能建立隐蔽信道,使本地恶意软件通过嵌入秘密的URL向攻击者泄露数据,在11个模型中成功率达79.7%。
中文摘要 AI 辅助
随着大型语言模型(LLM)和基于LLM的智能体能力的不断增强,用户越来越多地使用它们来解决日常问题,例如回复电子邮件或提供编程支持。已有工作广泛研究了安全和隐私风险,例如提示注入以及向聊天机器人提供商泄露敏感数据。尽管开发了各种解决方案来应对这些风险,包括通过输入结构化来防止提示注入,或部署本地LLM以避免与聊天机器人运营商共享机密数据,但LLM仍然存在向第三方泄露机密数据的风险。在本文中,我们通过LLMLeak展示了一种新颖的攻击向量,其中在本地运行但无法直接与互联网通信的恶意软件滥用LLM来建立隐蔽信道。虽然指示LLM通过生成的代码直接发送数据的输入很容易被检测到,并且网络库通常受到限制,但LLMLeak仅依赖LLM的工具来获取网站以获取进一步信息。客户端上的恶意软件组件将秘密嵌入到URL中。它将被引用的网站呈现为提供良性任务所需的信息,例如迁移软件库。当LLM访问该URL时,攻击者通过攻击者控制的DNS或Web服务器接收编码后的秘密。我们对十一个开放参数模型进行了广泛评估,观察到79.7%的攻击成功率,并对真实世界的聊天机器人进行了案例研究,证明了LLMLeak的相关性。
英文摘要
With the increasing capabilities of Large-Language-Models (LLMs) and LLM-based agents, users are increasingly using them to solve everyday problems, such as answering e-mails or providing programming support. Existing work has extensively investigated security and privacy risks, such as prompt injections and the disclosure of sensitive data to chatbot providers. While various solutions were developed to address these risks, including input structuring to prevent prompt injections or deploying local LLMs to avoid sharing confidential data with chatbot operators, LLMs also pose the risk of leaking confidential data to third parties. In this paper, we demonstrate with LLMLeak a novel attack vector where malicious software that runs locally but cannot communicate directly with the internet abuses LLMs to establish a covert channel. While inputs that instruct the LLM to send data directly via generated code are easy to detect and network libraries are typically restricted, LLMLeak relies only on the LLM's tool to fetch websites for further information. A malicious software component on the client side embeds a secret into a URL. It presents the referenced website as providing information required for a benign task, such as migrating a software library. When the LLM accesses the URL, the attacker receives the encoded secret through an attacker-controlled DNS or web server. We perform an extensive evaluation on eleven open-parameter models, observe an attack success rate of 79.7%, and also conduct a case study on real-world chatbots, demonstrating the relevance of LLMLeak.