测试大模型自动生成钓鱼网站的能力,揭示其潜在安全风险。
Assessing Spear-Phishing Website Generation in Large Language Model Coding Agents
- 用40个不同大模型生成钓鱼网站代码,评估其攻击性能力。
- 发现部分模型更易生成可被黑客利用的恶意代码,且与模型规模相关。
- 公开200个网站代码和日志数据集,供安全研究使用。
大型语言模型正从人类辅助工具演变为能自主观察环境、推理问题、修改系统并理解行动后果的独立智能体。在编程领域,这类模型已能协助人类生成代码并控制开发环境或网络系统。然而,随着其能力增强,滥用风险也日益突出。尤其在网络安全领域,模型可能被用于扩大社交工程攻击的威胁,因它们可自主完成本需熟练程序员耗时完成的任务。尽管这一风险令人担忧,但现有研究对大模型在生成社会工程攻击代码方面的能力评估仍十分有限。本文对比了多种大模型生成潜在危险代码基的能力与意愿,构建了一个包含200个网站代码及40个大模型编码代理日志的数据集。分析表明,某些模型指标(如参数量)与生成钓鱼网站的能力呈显著相关性。该研究结果及数据集将为关注大模型滥用防范的研究者与从业者提供重要参考。
原文摘要 · Abstract (English)
Large Language Models are expanding beyond being a tool humans use and into independent agents that can observe an environment, reason about solutions to problems, make changes that impact those environments, and understand how their actions impacted their environment. One of the most common applications of these LLM Agents is in computer programming, where agents can successfully work alongside humans to generate code while controlling programming environments or networking systems. However, with the increasing ability and complexity of these agents comes dangers about the potential for their misuse. A concerning application of LLM agents is in the domain cybersecurity, where they have the potential to greatly expand the threat imposed by attacks such as social engineering. This is due to the fact that LLM Agents can work autonomously and perform many tasks that would normally require time and effort from skilled human programmers. While this threat is concerning, little attention has been given to assessments of the capabilities of LLM coding agents in generating code for social engineering attacks. In this work we compare different LLMs in their ability and willingness to produce potentially dangerous code bases that could be misused by cyberattackers. The result is a dataset of 200 website code bases and logs from 40 different LLM coding agents. Analysis of models shows which metrics of LLMs are more and less correlated with performance in generating spear-phishing sites. Our analysis and the dataset we present will be of interest to researchers and practitioners concerned in defending against the potential misuse of LLMs in spear-phishing.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。