用浏览器内运行的AI引导模糊测试,实时发现代理浏览器的提示注入漏洞。
In-Browser LLM-Guided Fuzzing for Real-Time Prompt Injection Testing in Agentic AI Browsers
- 在浏览器中运行的LLM引导模糊测试框架
- 可实时发现跨站提示注入漏洞,攻击者能操控用户代理行为
- 适合安全研究人员和开发者验证AI浏览器安全性
基于大语言模型(LLM)的代理已集成到网页浏览器中(常称为代理型AI浏览器),可实现网页任务的自动化。然而,这些代理易受间接提示注入攻击,恶意指令隐藏在网页中,诱导代理执行非预期操作。此类攻击可绕过传统网页安全边界,因AI代理以用户权限跨站点运行。本文提出一种全新的模糊测试框架,完全在浏览器中运行,并由LLM指导,可实时自动发现此类提示注入漏洞。
原文摘要 · Abstract (English)
Large Language Model (LLM) based agents integrated into web browsers (often called agentic AI browsers) offer powerful automation of web tasks. However, they are vulnerable to indirect prompt injection attacks, where malicious instructions hidden in a webpage deceive the agent into unwanted actions. These attacks can bypass traditional web security boundaries, as the AI agent operates with the user privileges across sites. In this paper, we present a novel fuzzing framework that runs entirely in the browser and is guided by an LLM to automatically discover such prompt injection vulnerabilities in real time.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。