研究如何检测和隐藏代码逆向中的提示注入攻击
Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents

- 在反编译输出中检测恶意提示注入字符串
- 提出混淆攻击手段及对应的防御方法
- 适合安全研究人员与逆向工程系统开发者
智能软件逆向工程系统可能受到嵌入可执行二进制文件源码中的提示注入攻击。本研究展示了在对抗性程序的反编译输出中检测提示注入字符串的防御策略。同时探讨了攻击的混淆方法及其后续防御机制。该研究深化了对智能软件分析系统风险与安全性的理解,为将其部署于生产级网络工作流提供了必要支持。
原文摘要 · Abstract (English)
Agentic software reverse engineering systems are vulnerable to prompt injection attacks placed into the source code of executable binary files. This research demonstrates defensive tactics for detecting the presences of prompt injection strings in the decompiler output of adversarial example programs. Methods for obfuscating these attacks and subsequent methods for defending against these obfuscations are also explored. This research advances the understanding of risk and security of agentic software analysis systems necessary for their deployment into production-level cyber workflows.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。