An Early Categorization of Prompt Injection Attacks on Large Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Rossi, Sippo, Michel, Alisia Marianne, Mukkamala, Raghava Rao, Thatcher, Jason Bennett
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910315987337216
author Rossi, Sippo
Michel, Alisia Marianne
Mukkamala, Raghava Rao
Thatcher, Jason Bennett
author_facet Rossi, Sippo
Michel, Alisia Marianne
Mukkamala, Raghava Rao
Thatcher, Jason Bennett
contents Large language models and AI chatbots have been at the forefront of democratizing artificial intelligence. However, the releases of ChatGPT and other similar tools have been followed by growing concerns regarding the difficulty of controlling large language models and their outputs. Currently, we are witnessing a cat-and-mouse game where users attempt to misuse the models with a novel attack called prompt injections. In contrast, the developers attempt to discover the vulnerabilities and block the attacks simultaneously. In this paper, we provide an overview of these emergent threats and present a categorization of prompt injections, which can guide future research on prompt injections and act as a checklist of vulnerabilities in the development of LLM interfaces. Moreover, based on previous literature and our own empirical research, we discuss the implications of prompt injections to LLM end users, developers, and researchers.
format Preprint
id arxiv_https___arxiv_org_abs_2402_00898
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle An Early Categorization of Prompt Injection Attacks on Large Language Models
Rossi, Sippo
Michel, Alisia Marianne
Mukkamala, Raghava Rao
Thatcher, Jason Bennett
Cryptography and Security
Computation and Language
Machine Learning
Large language models and AI chatbots have been at the forefront of democratizing artificial intelligence. However, the releases of ChatGPT and other similar tools have been followed by growing concerns regarding the difficulty of controlling large language models and their outputs. Currently, we are witnessing a cat-and-mouse game where users attempt to misuse the models with a novel attack called prompt injections. In contrast, the developers attempt to discover the vulnerabilities and block the attacks simultaneously. In this paper, we provide an overview of these emergent threats and present a categorization of prompt injections, which can guide future research on prompt injections and act as a checklist of vulnerabilities in the development of LLM interfaces. Moreover, based on previous literature and our own empirical research, we discuss the implications of prompt injections to LLM end users, developers, and researchers.
title An Early Categorization of Prompt Injection Attacks on Large Language Models
topic Cryptography and Security
Computation and Language
Machine Learning
url https://arxiv.org/abs/2402.00898