arXiv:2510.11398cs.CRcs.AI2025-10被引 2

未来本地大模型可能被黑客用于隐蔽攻击,威胁安全防御。

Living Off the LLM: How LLMs Will Change Adversary Tactics

  • 将本地大模型融入现有攻击流程,实现更隐蔽的入侵
  • 攻击者可利用模型生成伪造指令绕过检测机制
  • 适合安全研究人员与系统防护开发者关注

在‘就地取材’攻击中,恶意行为者利用系统上已存在的合法工具和进程以规避检测。本文探讨了未来部署在设备上的大语言模型(LLM)可能成为新的安全风险:攻击者将把本地LLM集成到其攻击链中,从而增强攻击的隐蔽性和智能化水平。同时,论文分析了安全社区可能采取的应对策略,包括模型行为监控、访问控制强化及异常行为识别等,以防范此类新型威胁。本研究揭示了大模型在终端环境中的潜在滥用风险,并为构建更鲁棒的防御体系提供思路。

原文摘要 · Abstract (English)

In living off the land attacks, malicious actors use legitimate tools and processes already present on a system to avoid detection. In this paper, we explore how the on-device LLMs of the future will become a security concern as threat actors integrate LLMs into their living off the land attack pipeline and ways the security community may mitigate this threat.

大模型安全攻击防御本地LLM

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。