arXiv:2412.17614cs.CRcs.AI2024-12被引 3

剖析大模型在安全上的新挑战,聚焦对抗攻击与供应链风险。

Emerging Security Challenges of Large Language Models

  • 对比传统机器学习模型,分析大模型独特漏洞机制。
  • 识别大模型对抗攻击的多种目标,如误导输出、信息泄露。
  • 揭示大模型供应链数据流动风险,适合安全研究者参考。

大语言模型(LLMs)在教育、医疗等重要领域迅速普及,因其开放性设计和通用性,被广泛用于文本生成、代码辅助及安全信息分析。尽管传统机器学习模型易受对抗攻击,但大模型的广泛部署引发了对其潜在安全影响的新担忧。本报告基于达克斯图尔研讨会上的工作组讨论,以ChatGPT为例,探讨四方面问题:大模型与传统模型在漏洞上的差异;大模型对抗攻击的目标;评估其风险的复杂性;以及大模型的供应链结构、数据流动路径及其安全影响。研究指出,尽管大模型可能被用于加速恶意开发,但其核心角色仍是工具性,而非主动攻击者。报告最后总结了当前面临的关键挑战与未来方向。

原文摘要 · Abstract (English)

Large language models (LLMs) have achieved record adoption in a short period of time across many different sectors including high importance areas such as education [4] and healthcare [23]. LLMs are open-ended models trained on diverse data without being tailored for specific downstream tasks, enabling broad applicability across various domains. They are commonly used for text generation, but also widely used to assist with code generation [3], and even analysis of security information, as Microsoft Security Copilot demonstrates [18]. Traditional Machine Learning (ML) models are vulnerable to adversarial attacks [9]. So the concerns on the potential security implications of such wide scale adoption of LLMs have led to the creation of this working group on the security of LLMs. During the Dagstuhl seminar on "Network Attack Detection and Defense - AI-Powered Threats and Responses", the working group discussions focused on the vulnerability of LLMs to adversarial attacks, rather than their potential use in generating malware or enabling cyberattacks. Although we note the potential threat represented by the latter, the role of the LLMs in such uses is mostly as an accelerator for development, similar to what it is in benign use. To make the analysis more specific, the working group employed ChatGPT as a concrete example of an LLM and addressed the following points, which also form the structure of this report: 1. How do LLMs differ in vulnerabilities from traditional ML models? 2. What are the attack objectives in LLMs? 3. How complex it is to assess the risks posed by the vulnerabilities of LLMs? 4. What is the supply chain in LLMs, how data flow in and out of systems and what are the security implications? We conclude with an overview of open challenges and outlook.

大模型安全对抗攻击供应链风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。