黑客利用网页链接漏洞欺骗大模型多智能体系统,攻击门槛低且破坏力强。
Web Fraud Attacks Against LLM-Driven Multi-Agent Systems
- 设计12种链接欺诈手法,如相似字符伪装、目录嵌套、参数混淆
- 实验显示攻击在多种系统架构下均有效,成功率高且无需复杂输入设计
- 揭示多智能体系统安全新风险,适合关注AI安全的研究者参考
随着大模型驱动的多智能体系统(MAS)的普及,网络链接的安全性成为关键问题。一旦多智能体系统被诱导信任恶意链接,攻击者即可借此扩展攻击面。本文提出一种新型攻击——网页欺诈攻击(Web Fraud Attacks),通过操纵网页链接的独特结构来欺骗多智能体系统。我们设计了12种典型攻击变体,涵盖同形异义字符欺骗、子目录嵌套和参数混淆等多种方法。在多个攻击向量上的广泛实验表明,此类攻击不仅在不同多智能体系统架构中展现出显著破坏力,还具备独特规避优势:无需复杂输入设计,大幅降低攻击门槛。这些结果凸显了应对网页欺诈攻击的重要性,为多智能体系统安全提供了新视角。代码已开源:https://github.com/JiangYingEr/Web-Fraud-Attack-in-MAS。
原文摘要 · Abstract (English)
With the proliferation of LLM-driven multi-agent systems (MAS), the security of Web links has become a critical concern. Once MAS is induced to trust a malicious link, attackers can use it as a springboard to expand the attack surface. In this paper, we propose Web Fraud Attacks, a novel type of attack manipulating unique structures of web links to deceive MAS. We design 12 representative attack variants that encompass various methods, such as homoglyph deception, sub-directory nesting, and parameter obfuscation. Through extensive experiments on these attack vectors, we demonstrate that Web fraud attacks not only exhibit significant destructive potential across different MAS architectures but also possess a distinct advantage in evasion: they circumvent the need for complex input design, lowering the threshold for attacks significantly. These results underscore the importance of addressing Web fraud attacks, providing new insights into MAS safety. Our code is available at https://github.com/JiangYingEr/Web-Fraud-Attack-in-MAS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。