prompt注入已演变为多阶段恶意软件攻击链,威胁真实系统安全。
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
- 提出七阶段'promptware杀伤链'模型,类比传统黑客攻击流程。
- 分析36起案例,21次攻击跨越4个以上阶段,证明威胁真实存在。
- 适合关注大模型安全的开发者与安全工程师阅读。
Prompt注入最初被视为大语言模型(LLM)对SQL注入的类比。然而,过去三年中,被标记为提示注入的攻击已从孤立的输入操纵漏洞,演变为类似恶意软件的多步骤攻击机制。本文主张,提示注入已发展为一种新型恶意软件执行机制——‘promptware’,通过精心设计的提示触发应用程序中LLM的漏洞。我们提出一个七阶段的promptware杀伤链:初始访问(提示注入)、权限提升(越狱)、侦察、持久化(内存与检索污染)、命令与控制、横向移动及目标行动。分析了36个著名研究与真实世界事件,涉及生产级LLM系统,发现至少21次攻击跨越四个或更多阶段,表明该威胁模型并非理论假设。文章呼吁采用纵深防御策略,覆盖整个promptware生命周期,并回顾各阶段的可行应对措施。通过将讨论从‘提示注入’转向‘promptware杀伤链’,本工作提供分析清晰度,支持结构化风险评估,并为基于LLM系统的系统性安全工程奠定基础。
原文摘要 · Abstract (English)
Prompt injection was initially framed as the large language model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated input-manipulation exploits into multistep attack mechanisms that resemble malware. In this paper, we argue that prompt injections evolved into promptware, a new class of malware execution mechanism triggered through prompts engineered to exploit an application's LLM. We introduce a seven-stage promptware kill chain: Initial Access (prompt injection), Privilege Escalation (jailbreaking), Reconnaissance, Persistence (memory and retrieval poisoning), Command and Control, Lateral Movement, and Actions on Objective. We analyze thirty-six prominent studies and real-world incidents affecting production LLM systems and show that at least twenty-one documented attacks that traverse four or more stages of this kill chain, demonstrating that the threat model is not merely theoretical. We discuss the need for a defense-in-depth approach that addresses all stages of the promptware life cycle and review relevant countermeasures for each step. By moving the conversation from prompt injection to a promptware kill chain, our work provides analytical clarity, enables structured risk assessment, and lays a foundation for systematic security engineering of LLM-based systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。