arXiv:2505.11449cs.CRcs.AI2025-05被引 10

LLMs让黑客能精准打击用户,实现个性化勒索

LLMs unlock new paths to monetizing exploits

  • 用LLM自动发现目标软件的大量易检漏洞
  • 可识别个人敏感信息用于定向勒索,如邮件中的私密内容
  • 适合安全研究者与防御团队关注新型攻击威胁

我们指出,大型语言模型(LLMs)将很快改变网络攻击的经济模式。攻击者不再针对最常用软件、以最低成本受害者为目标,而是利用LLM实现用户级定制攻击。在漏洞挖掘方面,无需人工手动寻找百万用户产品中的难识别漏洞,LLM可自动发现数千用户产品中的数千个易识别漏洞;在勒索变现方面,传统通用勒索软件统一加密所有数据并索要赎金,而基于LLM的勒索攻击可依据被攻设备内容定制勒索要求。我们证明这些攻击(包括若干变体)已可通过当前先进LLM实际实施。例如,仅通过自动化分析,一个无须人工干预的LLM即可在Enron邮件数据集中发现高度敏感信息(如高管与员工的婚外情),可用于敲诈。尽管部分攻击当前成本仍过高,但随着LLM成本下降,实施动机将持续上升。因此,我们必须建立新的纵深防御体系应对这一新威胁。

原文摘要 · Abstract (English)

We argue that Large language models (LLMs) will soon alter the economics of cyberattacks. Instead of attacking the most commonly used software and monetizing exploits by targeting the lowest common denominator among victims, LLMs enable adversaries to launch tailored attacks on a user-by-user basis. On the exploitation front, instead of human attackers manually searching for one difficult-to-identify bug in a product with millions of users, LLMs can find thousands of easy-to-identify bugs in products with thousands of users. And on the monetization front, instead of generic ransomware that always performs the same attack (encrypt all your data and request payment to decrypt), an LLM-driven ransomware attack could tailor the ransom demand based on the particular content of each exploited device. We show that these two attacks (and several others) are imminently practical using state-of-the-art LLMs. For example, we show that without any human intervention, an LLM finds highly sensitive personal information in the Enron email dataset (e.g., an executive having an affair with another employee) that could be used for blackmail. While some of our attacks are still too expensive to scale widely today, the incentives to implement these attacks will only increase as LLMs get cheaper. Thus, we argue that LLMs create a need for new defense-in-depth approaches.

网络安全智能攻击勒索软件大模型风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。