IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Wu, Yuhao, Roesner, Franziska, Kohno, Tadayoshi, Zhang, Ning, Iqbal, Umar
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916591194603520
author Wu, Yuhao
Roesner, Franziska
Kohno, Tadayoshi
Zhang, Ning
Iqbal, Umar
author_facet Wu, Yuhao
Roesner, Franziska
Kohno, Tadayoshi
Zhang, Ning
Iqbal, Umar
contents Large language models (LLMs) extended as systems, such as ChatGPT, have begun supporting third-party applications. These LLM apps leverage the de facto natural language-based automated execution paradigm of LLMs: that is, apps and their interactions are defined in natural language, provided access to user data, and allowed to freely interact with each other and the system. These LLM app ecosystems resemble the settings of earlier computing platforms, where there was insufficient isolation between apps and the system. Because third-party apps may not be trustworthy, and exacerbated by the imprecision of natural language interfaces, the current designs pose security and privacy risks for users. In this paper, we evaluate whether these issues can be addressed through execution isolation and what that isolation might look like in the context of LLM-based systems, where there are arbitrary natural language-based interactions between system components, between LLM and apps, and between apps. To that end, we propose IsolateGPT, a design architecture that demonstrates the feasibility of execution isolation and provides a blueprint for implementing isolation, in LLM-based systems. We evaluate IsolateGPT against a number of attacks and demonstrate that it protects against many security, privacy, and safety issues that exist in non-isolated LLM-based systems, without any loss of functionality. The performance overhead incurred by IsolateGPT to improve security is under 30% for three-quarters of tested queries.
format Preprint
id arxiv_https___arxiv_org_abs_2403_04960
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
Wu, Yuhao
Roesner, Franziska
Kohno, Tadayoshi
Zhang, Ning
Iqbal, Umar
Cryptography and Security
Artificial Intelligence
Computation and Language
Computers and Society
Machine Learning
Large language models (LLMs) extended as systems, such as ChatGPT, have begun supporting third-party applications. These LLM apps leverage the de facto natural language-based automated execution paradigm of LLMs: that is, apps and their interactions are defined in natural language, provided access to user data, and allowed to freely interact with each other and the system. These LLM app ecosystems resemble the settings of earlier computing platforms, where there was insufficient isolation between apps and the system. Because third-party apps may not be trustworthy, and exacerbated by the imprecision of natural language interfaces, the current designs pose security and privacy risks for users. In this paper, we evaluate whether these issues can be addressed through execution isolation and what that isolation might look like in the context of LLM-based systems, where there are arbitrary natural language-based interactions between system components, between LLM and apps, and between apps. To that end, we propose IsolateGPT, a design architecture that demonstrates the feasibility of execution isolation and provides a blueprint for implementing isolation, in LLM-based systems. We evaluate IsolateGPT against a number of attacks and demonstrate that it protects against many security, privacy, and safety issues that exist in non-isolated LLM-based systems, without any loss of functionality. The performance overhead incurred by IsolateGPT to improve security is under 30% for three-quarters of tested queries.
title IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Computers and Society
Machine Learning
url https://arxiv.org/abs/2403.04960