发现GPT知识文件泄露五大途径,代码解释器漏洞可95.95%下载原始文件
When GPT Spills the Tea: Comprehensive Assessment of Knowledge File Leakage in GPTs
- 基于DSPM框架分析65万条元数据,识别出五类知识泄露路径
- 代码解释器激活后可95.95%成功下载原始知识文件,28.80%涉版权内容
- 适合GPT开发者与平台方参考,提升数据供应链安全性
知识文件广泛用于大语言模型代理(如GPT)以提升回复质量,但其泄露风险日益突出。现有研究已表明,对抗性提示可诱发GPT泄露知识文件内容。然而,鉴于GPT中客户端、服务器与数据库间复杂的数据流,仍不确定是否存在其他泄露途径。本文通过受数据安全态势管理(DSPM)启发的新工作流程,对651,022条GPT元数据、11,820条数据流及1,466条响应进行分析,识别出五类泄露向量:元数据、GPT初始化、检索、沙箱执行环境与提示词。这些向量使攻击者可提取敏感知识文件信息,包括标题、内容、类型与大小。值得注意的是,启用内置工具「代码解释器」会引发权限提升漏洞,使攻击者以95.95%成功率直接下载原始知识文件。进一步分析显示,28.80%的泄露文件涉及版权内容,包括主要出版社的数字副本及某上市公司的内部材料。最后,本文为GPT构建者与平台提供可行的解决方案,以保障GPT数据供应链安全。
原文摘要 · Abstract (English)
Knowledge files have been widely used in large language model (LLM) agents, such as GPTs, to improve response quality. However, concerns about the potential leakage of knowledge files have grown significantly. Existing studies demonstrate that adversarial prompts can induce GPTs to leak knowledge file content. Yet, it remains uncertain whether additional leakage vectors exist, particularly given the complex data flows across clients, servers, and databases in GPTs. In this paper, we present a comprehensive risk assessment of knowledge file leakage, leveraging a novel workflow inspired by Data Security Posture Management (DSPM). Through the analysis of 651,022 GPT metadata, 11,820 flows, and 1,466 responses, we identify five leakage vectors: metadata, GPT initialization, retrieval, sandboxed execution environments, and prompts. These vectors enable adversaries to extract sensitive knowledge file data such as titles, content, types, and sizes. Notably, the activation of the built-in tool Code Interpreter leads to a privilege escalation vulnerability, enabling adversaries to directly download original knowledge files with a 95.95% success rate. Further analysis reveals that 28.80% of leaked files are copyrighted, including digital copies from major publishers and internal materials from a listed company. In the end, we provide actionable solutions for GPT builders and platform providers to secure the GPT data supply chain.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。