From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
从提示注入到协议利用:LLM驱动的AI代理工作流中的威胁
机构 * Department of Computer and Network Engineering, College of Information Technology, United Arab Emirates University(阿联酋大学计算机与网络工程系) ; Technology Innovation Institute(技术创新研究所) ; Eötvös Loránd University(埃奥瓦大学) ; Department of Computer Science, Guelma University(古尔马大学计算机科学系) ; De Montfort University(德蒙福特大学) ; Khalifa University of Science and Technology(卡里玛科学技术大学)
专题命中 工作流自动化 :AI agent(title,abstract);agent(abstract);agentic(abstract);分类 cs.AI
AI总结 本文提出了一种统一的端到端威胁模型,系统分类了LLM代理生态系统中的三十多种攻击技术,涵盖输入操纵、模型妥协、系统和隐私攻击及协议漏洞,并提供缓解策略以设计安全的代理AI系统。
Comments The paper is published in ICT Express (Elsevier)