arXiv:2410.13919cs.CRcs.AI2024-10被引 24

用蜜罐监测网络中自主攻击的AI黑客,发现800万次攻击中有8个疑似AI代理。

LLM Agent Honeypot: Monitoring AI Hacking Agents in the Wild

  • 在标准SSH蜜罐上添加提示注入和时间分析,识别自主攻击的AI代理。
  • 三个月内捕获813万次攻击,发现8个疑似由大模型驱动的攻击者。
  • 为检测真实世界中的恶意AI黑客提供早期预警,适合安全研究人员参考。

由大型语言模型(LLM)驱动的攻击正对现代网络安全构成日益增长的威胁。为应对这一挑战,我们提出LLM Honeypot系统,用于监控自主的AI黑客代理。通过在标准SSH蜜罐基础上引入提示注入与基于时间的分析技术,该框架旨在从各类攻击者中识别出LLM代理。在公开环境中为期约三个月的部署中,共收集到8,130,731次攻击尝试,识别出8个潜在的AI攻击代理。本研究揭示了AI驱动威胁的出现及其当前使用水平,可作为真实世界中恶意LLM代理的早期预警。

原文摘要 · Abstract (English)

Attacks powered by Large Language Model (LLM) agents represent a growing threat to modern cybersecurity. To address this concern, we present LLM Honeypot, a system designed to monitor autonomous AI hacking agents. By augmenting a standard SSH honeypot with prompt injection and time-based analysis techniques, our framework aims to distinguish LLM agents among all attackers. Over a trial deployment of about three months in a public environment, we collected 8,130,731 hacking attempts and 8 potential AI agents. Our work demonstrates the emergence of AI-driven threats and their current level of usage, serving as an early warning of malicious LLM agents in the wild.

AI安全蜜罐大模型攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。