针对增强现实大模型社交工程攻击,提出跨栈防御系统UNSEEN。
UNSEEN: A Cross-Stack LLM Unlearning Defense against AR-LLM Social Engineering Attacks

- 通过AR访问控制层实现身份授权感知,防止非法信息采集
- 基于F-RMU的模型遗忘技术抑制敏感人物画像生成,降低隐私泄露风险
- 运行时代理防护机制动态管控交互策略,抵御自适应社交工程
基于AR-LLM的社交工程攻击(如SEAR)正对现实社会生活构成重大威胁。攻击者利用增强现实眼镜捕获目标的图像与语音信息,借助大语言模型识别目标并生成社交档案,再通过LLM代理实施社交工程策略以获取信任并完成钓鱼。现有防御手段如基于角色的访问控制或数据流追踪,难以适用于融合了嵌入式AR设备与黑盒大模型推理的复杂生态。为此,我们提出UNSEEN——一种跨栈协同防御框架,包含:用于身份授权感知的AR访问控制层、基于F-RMU的大模型遗忘机制以抑制敏感画像生成、以及运行时代理护栏实现自适应交互控制。我们在一项经IRB批准的用户研究中评估该系统,涵盖60名参与者和360条在真实社交场景中标注的对话数据。
原文摘要 · Abstract (English)
Emerging AR-LLM-based Social Engineering attack (e.g., SEAR) is at the edge of posing great threats to real-world social life. In such AR-LLM-SE attack, the attacker can leverage AR (Augmented Reality) glass to capture the image and vocal information of the target, using the LLM to identify the target and generate the social profile, using the LLM agents to apply social engineering strategies for conversation suggestion to win the target trust and perform phishing afterwards. Current defensive approaches, such as role-based access control or data flow tracking, are not directly applicable to the convergent AR-LLM ecosystem (considering embedded AR device and opaque LLM inference), leaving an emerging and potent social engineering threat that existing privacy paradigms are ill-equipped to address. This necessitates a shift beyond solely human-centric measures like legislation and user education toward enforceable vendor policies and platform-level restrictions. Realizing this vision, however, faces significant technical challenges: securing resource-constrained AR-embedded devices, implementing fine-grained access control within opaque LLM inferences, and governing adaptive interactive agents. To address these challenges, we present UNSEEN, a coordinated cross-stack defense that combines an AR ACL (Access Control Layer) for identity-gated sensing, F-RMU-based LLM unlearning for sensitive profile suppression, and runtime agent guardrails for adaptive interaction control. We evaluate UNSEEN in an IRB-approved user study with 60 participants and a dataset of 360 annotated conversations across realistic social scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。