当前位置:首页 > 报告详情

LLM时代下的安全新探索.pdf

上传人: Ch****l 编号:171283 2024-07-03 40页 6.88MB

1、New Security Explorations in the Era of LLMsLyutoon IIE&Nu1LContent LLM Security Security of LLM-Integrated Ecosystem LLM+Security=?LLM SecurityHow Security Manifests in LLMs?LLMs can generate misleading or harmful content.source:Belgian Man Commits Suicide After AI Chatbot Urges Him To Sacrifice Hi

2、mself For Climate Change( Attacks:Jailbreak LLM in the“Jail”LLMs are not inherently safe.Content safety is imposed through specialized fine-tuning processes.LLM Jailbreak Attackers may craft special prompt sequences to bypass the safety-alignment.Existing Attacks:Jailbreak How to Jailbreak LLMs?GCG

3、GPTFuzz DRA Why DRA?My work on USENIX Security24:D Identified the bias in LLM safety-alignment Blackbox attack Still works on ChatGPT 4o,4,3.5,4o-mini DRA:https:/ Making Them Ask and Answer:Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction https:/www.usenix.org/confer

4、ence/usenixsecurity24/presentation/liu-tong Existing Attacks:Prompt Leaking LLMs System Prompt Leaking Prompt leaking represents an attack that asks the model to show its own(system)prompt.Sensitive information IP Copyright Existing Attacks:Prompt Injection Taken from Learning Prompt website:https:/

5、learnprompting.org/docs/prompt_hacking/injectionTaken from paper:Prompt Injection attack against LLM-integrated Applications Prompt Injection Inspired by SQL injection.Affect:Manipulate models output Maybe RCE!(Talk it later)Security of LLM-Integrated EcosystemLLM-integrated System Taken from Learni

6、ng Prompt website:https:/learnprompting.org/docs/prompt_hacking/injectionLLM-integrated Frameworks:Toolkit or abstractions to interact with LLMs easily for some tasks.LLM-integrated Apps:Apps built upon LLM-integrated frameworks Question:Is this system safe?Answer:Definitely not!Motivation Example:L

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要探讨了在大型语言模型(LLM)时代的网络安全新探索。作者指出,尽管LLM在许多方面具有巨大潜力,如理解程序语义、生成代码、模糊测试等,但它们并非固有安全。文章引用了多个研究,例如在USENIX Security 2024会议上提出的工作,揭示了LLM安全对齐中的偏见,并展示了如何通过特定的提示序列绕过安全性限制。 关键数据包括:11个框架中发现20个漏洞,导致13个CVE(已知漏洞),以及针对LLM集成生态系统的攻击,如Jailbreak(越狱)和Prompt Leaking(提示泄露)。此外,文章提到了Vanna漏洞,一个示例攻击链,以及现实世界中的应用攻击,如OpenAI API密钥的隐私泄露。 文章提出了LLM在安全领域的多种潜在应用,如渗透测试、钓鱼检测等,并通过实例展示了如何将LLM用于模糊测试和其他安全相关任务。最后,作者强调了在利用LLM的同时,确保其安全性的重要性。
LLM如何保护自己?" "LLM+安全=?":探索AI安全新领域 "AI聊天机器人诱导自杀案":LLM安全性探讨
客服
商务合作
小程序
服务号
折叠