arXiv:2410.14569cs.CRcs.AI2024-10被引 36

LLM Agent结合网络工具可高效实施精准网络攻击

When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs

  • 用LLM Agent自动执行网络攻击任务,搭配网页工具增强能力
  • 收集个人身份信息准确率达95.9%,伪造内容93.9%被认作真实
  • 低成本高效率,现有防护机制难以阻止此类攻击

大型语言模型(LLMs)已发展为具备规划与工具交互能力的智能体。这些智能体常与网络工具结合,获取多样信息与实时数据。尽管带来诸多应用优势,也加剧了恶意使用风险,尤其在涉及个人数据的网络攻击中。本文研究了LLM智能体在攻击中的潜在危害:1)其执行网络攻击的能力有多强;2)网络工具如何提升攻击效果;3)利用它们发动攻击的成本与难度。实验涵盖三类场景:个人身份信息(PII)收集、仿冒内容生成、鱼叉式网络钓鱼邮件制作。结果显示,LLM智能体在信息收集中精度达95.9%,生成的仿冒内容中93.9%被判定为真实,鱼叉式钓鱼邮件点击率提升46.67%。同时发现当前主流商业LLM的安全防护存在明显漏洞,亟需加强防范措施。

原文摘要 · Abstract (English)

Recent advancements in Large Language Models (LLMs) have established them as agentic systems capable of planning and interacting with various tools. These LLM agents are often paired with web-based tools, enabling access to diverse sources and real-time information. Although these advancements offer significant benefits across various applications, they also increase the risk of malicious use, particularly in cyberattacks involving personal information. In this work, we investigate the risks associated with misuse of LLM agents in cyberattacks involving personal data. Specifically, we aim to understand: 1) how potent LLM agents can be when directed to conduct cyberattacks, 2) how cyberattacks are enhanced by web-based tools, and 3) how affordable and easy it becomes to launch cyberattacks using LLM agents. We examine three attack scenarios: the collection of Personally Identifiable Information (PII), the generation of impersonation posts, and the creation of spear-phishing emails. Our experiments reveal the effectiveness of LLM agents in these attacks: LLM agents achieved a precision of up to 95.9% in collecting PII, generated impersonation posts where 93.9% of them were deemed authentic, and boosted click rate of phishing links in spear phishing emails by 46.67%. Additionally, our findings underscore the limitations of existing safeguards in contemporary commercial LLMs, emphasizing the urgent need for robust security measures to prevent the misuse of LLM agents.

大模型安全网络攻击隐私泄露智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。