研究发现大模型通过网页搜索工具易被间接注入攻击,暴露严重安全漏洞。
Exploiting Web Search Tools of AI Agents for Data Exfiltration
- 利用间接提示注入攻击,操控大模型调用网页搜索工具
- 即使知名攻击模式仍有效,表明防御机制存在持续缺陷
- 适合关注AI安全、模型防护的开发者与研究人员
大型语言模型(LLMs)如今常被用于自主执行复杂任务,包括自然语言处理和动态工作流如网络搜索。工具调用与检索增强生成(RAG)使模型能处理并检索敏感企业数据,既提升了功能也放大了被滥用的风险。随着大模型越来越多地接入外部数据源,间接提示注入成为关键且不断演化的攻击向量,攻击者可通过操纵输入来利用模型。通过对多种模型进行系统性评估,我们分析了当前大模型对这类攻击的脆弱性,以及模型规模、制造商、具体实现等因素如何影响其安全性,并识别出最有效的攻击方法。结果表明,即便已知的攻击模式依然成功,揭示了模型防御中的持久弱点。为应对这些漏洞,我们强调需加强训练以提升内在韧性,建立集中式攻击向量数据库以实现主动防御,并构建统一测试框架以确保持续安全验证。这些措施对推动开发者将安全融入大模型核心设计至关重要,因为我们的研究显示,现有模型仍无法缓解长期存在的威胁。
原文摘要 · Abstract (English)
Large language models (LLMs) are now routinely used to autonomously execute complex tasks, from natural language processing to dynamic workflows like web searches. The usage of tool-calling and Retrieval Augmented Generation (RAG) allows LLMs to process and retrieve sensitive corporate data, amplifying both their functionality and vulnerability to abuse. As LLMs increasingly interact with external data sources, indirect prompt injection emerges as a critical and evolving attack vector, enabling adversaries to exploit models through manipulated inputs. Through a systematic evaluation of indirect prompt injection attacks across diverse models, we analyze how susceptible current LLMs are to such attacks, which parameters, including model size and manufacturer, specific implementations, shape their vulnerability, and which attack methods remain most effective. Our results reveal that even well-known attack patterns continue to succeed, exposing persistent weaknesses in model defenses. To address these vulnerabilities, we emphasize the need for strengthened training procedures to enhance inherent resilience, a centralized database of known attack vectors to enable proactive defense, and a unified testing framework to ensure continuous security validation. These steps are essential to push developers toward integrating security into the core design of LLMs, as our findings show that current models still fail to mitigate long-standing threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。