LPCI攻击将隐藏指令藏入系统记忆,跨会话触发越权行为。
Logic layer Prompt Control Injection (LPCI): A Novel Security Vulnerability Class in Agentic Systems
- 在内存、向量库或工具输出中嵌入编码延迟指令
- 可绕过输入过滤,在多会话中触发恶意行为
- 适用于研究LLM系统安全的开发者与安全工程师
大型语言模型(LLMs)在企业系统中的集成引入了新型隐蔽安全漏洞,尤其存在于逻辑执行层和持久化内存上下文中。本文提出一种名为逻辑层提示控制注入(Logic-layer Prompt Control Injection, LPCI)的新攻击类别,该类攻击将编码的、延迟触发且条件激活的恶意载荷嵌入内存、向量存储或工具输出中。这些载荷可绕过传统输入过滤机制,并在多个会话间触发未经授权的行为,对智能代理系统的安全性构成严重威胁。
原文摘要 · Abstract (English)
The integration of large language models (LLMs) into enterprise systems has introduced a new class of covert security vulnerabilities, particularly within logic execution layers and persistent memory contexts. This paper introduces Logic-layer Prompt Control Injection (LPCI), a novel category of attacks that embeds encoded, delayed, and conditionally triggered payloads within memory, vector stores, or tool outputs. These payloads can bypass conventional input filters and trigger unauthorised behaviour across sessions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。