A Security Risk Taxonomy for Prompt-Based Interaction With Large Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Derner, Erik, Batistič, Kristina, Zahálka, Jan, Babuška, Robert
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909322512957440
author Derner, Erik
Batistič, Kristina
Zahálka, Jan
Babuška, Robert
author_facet Derner, Erik
Batistič, Kristina
Zahálka, Jan
Babuška, Robert
contents As large language models (LLMs) permeate more and more applications, an assessment of their associated security risks becomes increasingly necessary. The potential for exploitation by malicious actors, ranging from disinformation to data breaches and reputation damage, is substantial. This paper addresses a gap in current research by specifically focusing on security risks posed by LLMs within the prompt-based interaction scheme, which extends beyond the widely covered ethical and societal implications. Our work proposes a taxonomy of security risks along the user-model communication pipeline and categorizes the attacks by target and attack type alongside the commonly used confidentiality, integrity, and availability (CIA) triad. The taxonomy is reinforced with specific attack examples to showcase the real-world impact of these risks. Through this taxonomy, we aim to inform the development of robust and secure LLM applications, enhancing their safety and trustworthiness.
format Preprint
id arxiv_https___arxiv_org_abs_2311_11415
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle A Security Risk Taxonomy for Prompt-Based Interaction With Large Language Models
Derner, Erik
Batistič, Kristina
Zahálka, Jan
Babuška, Robert
Cryptography and Security
Artificial Intelligence
Computation and Language
Human-Computer Interaction
Machine Learning
As large language models (LLMs) permeate more and more applications, an assessment of their associated security risks becomes increasingly necessary. The potential for exploitation by malicious actors, ranging from disinformation to data breaches and reputation damage, is substantial. This paper addresses a gap in current research by specifically focusing on security risks posed by LLMs within the prompt-based interaction scheme, which extends beyond the widely covered ethical and societal implications. Our work proposes a taxonomy of security risks along the user-model communication pipeline and categorizes the attacks by target and attack type alongside the commonly used confidentiality, integrity, and availability (CIA) triad. The taxonomy is reinforced with specific attack examples to showcase the real-world impact of these risks. Through this taxonomy, we aim to inform the development of robust and secure LLM applications, enhancing their safety and trustworthiness.
title A Security Risk Taxonomy for Prompt-Based Interaction With Large Language Models
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Human-Computer Interaction
Machine Learning
url https://arxiv.org/abs/2311.11415