arXiv:2502.11358cs.AIcs.CR2025-02ACL被引 10

动态生成恶意指令,绕过检测窃取LLM系统敏感信息

Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System

论文配图:Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System
图 1 · 摘自论文原文
  • 基于模仿熟悉行为,从上游工具推断信息生成指令
  • 攻击成功率提升13.2%,在新系统上仍有效
  • 适合研究模型安全与防御的开发者参考

信息窃取攻击对大语言模型(LLM)工具学习系统构成重大威胁。攻击者可通过被污染的工具注入恶意命令,诱导LLM将敏感信息发送至这些工具,导致隐私泄露。现有攻击方法多为黑盒且依赖静态指令,无法随用户查询和工具调用链变化而调整,易被检测并失败。本文提出AutoCMD,一种面向信息窃取攻击的动态命令生成方法。受‘模仿熟悉’概念启发,AutoCMD通过在开源系统上学习并结合目标系统样例进行强化,推断工具链中上游工具使用的数据,从而生成更精准的窃取指令。评估显示,AutoCMD相比基线提升13.2%的$ASR_{Theft}$,且可泛化至新工具学习系统以暴露其信息泄漏风险。此外,我们设计了四种防御方法,有效保护系统免受此类攻击。

原文摘要 · Abstract (English)

Information theft attacks pose a significant risk to Large Language Model (LLM) tool-learning systems. Adversaries can inject malicious commands through compromised tools, manipulating LLMs to send sensitive information to these tools, which leads to potential privacy breaches. However, existing attack approaches are black-box oriented and rely on static commands that cannot adapt flexibly to the changes in user queries and the invocation chain of tools. It makes malicious commands more likely to be detected by LLM and leads to attack failure. In this paper, we propose AutoCMD, a dynamic attack comment generation approach for information theft attacks in LLM tool-learning systems. Inspired by the concept of mimicking the familiar, AutoCMD is capable of inferring the information utilized by upstream tools in the toolchain through learning on open-source systems and reinforcement with target system examples, thereby generating more targeted commands for information theft. The evaluation results show that AutoCMD outperforms the baselines with +13.2% $ASR_{Theft}$, and can be generalized to new tool-learning systems to expose their information leakage risks. We also design four defense methods to effectively protect tool-learning systems from the attack.

信息窃取LLM安全动态指令工具学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。