arXiv:2412.06090cs.CRcs.AI2024-12被引 16

揭露提示注入如何破坏AI安全三要素,威胁真实系统

Trust No AI: Prompt Injection Along The CIA Security Triad

  • 通过真实案例展示提示注入攻击如何突破AI系统防护
  • 证实该攻击已导致多家头部厂商产品出现漏洞
  • 适合关注AI安全与对抗攻防的研究者和工程师

保密性、完整性、可用性构成信息安全基石。随着大语言模型应用兴起,2022年首次发现新型威胁——提示注入攻击。此后,大量真实世界漏洞和利用案例被记录,涉及OpenAI、Microsoft、Anthropic、Google等主流厂商的生产级LLM系统。本文基于作者研究及公开资料,整理真实攻击实例与概念验证,揭示提示注入如何破坏安全三要素,对人工智能系统及整体网络安全构成持续威胁。

原文摘要 · Abstract (English)

The CIA security triad - Confidentiality, Integrity, and Availability - is a cornerstone of data and cybersecurity. With the emergence of large language model (LLM) applications, a new class of threat, known as prompt injection, was first identified in 2022. Since then, numerous real-world vulnerabilities and exploits have been documented in production LLM systems, including those from leading vendors like OpenAI, Microsoft, Anthropic and Google. This paper compiles real-world exploits and proof-of concept examples, based on the research conducted and publicly documented by the author, demonstrating how prompt injection undermines the CIA triad and poses ongoing risks to cybersecurity and AI systems at large.

AI安全提示注入攻击防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。