The Best Defense is a Good Offense: Countering LLM-Powered Cyberattacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ayzenshteyn, Daniel, Weiss, Roy, Mirsky, Yisroel
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929551625420800
author Ayzenshteyn, Daniel
Weiss, Roy
Mirsky, Yisroel
author_facet Ayzenshteyn, Daniel
Weiss, Roy
Mirsky, Yisroel
contents As large language models (LLMs) continue to evolve, their potential use in automating cyberattacks becomes increasingly likely. With capabilities such as reconnaissance, exploitation, and command execution, LLMs could soon become integral to autonomous cyber agents, capable of launching highly sophisticated attacks. In this paper, we introduce novel defense strategies that exploit the inherent vulnerabilities of attacking LLMs. By targeting weaknesses such as biases, trust in input, memory limitations, and their tunnel-vision approach to problem-solving, we develop techniques to mislead, delay, or neutralize these autonomous agents. We evaluate our defenses under black-box conditions, starting with single prompt-response scenarios and progressing to real-world tests using custom-built CTF machines. Our results show defense success rates of up to 90\%, demonstrating the effectiveness of turning LLM vulnerabilities into defensive strategies against LLM-driven cyber threats.
format Preprint
id arxiv_https___arxiv_org_abs_2410_15396
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Best Defense is a Good Offense: Countering LLM-Powered Cyberattacks
Ayzenshteyn, Daniel
Weiss, Roy
Mirsky, Yisroel
Cryptography and Security
Artificial Intelligence
As large language models (LLMs) continue to evolve, their potential use in automating cyberattacks becomes increasingly likely. With capabilities such as reconnaissance, exploitation, and command execution, LLMs could soon become integral to autonomous cyber agents, capable of launching highly sophisticated attacks. In this paper, we introduce novel defense strategies that exploit the inherent vulnerabilities of attacking LLMs. By targeting weaknesses such as biases, trust in input, memory limitations, and their tunnel-vision approach to problem-solving, we develop techniques to mislead, delay, or neutralize these autonomous agents. We evaluate our defenses under black-box conditions, starting with single prompt-response scenarios and progressing to real-world tests using custom-built CTF machines. Our results show defense success rates of up to 90\%, demonstrating the effectiveness of turning LLM vulnerabilities into defensive strategies against LLM-driven cyber threats.
title The Best Defense is a Good Offense: Countering LLM-Powered Cyberattacks
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2410.15396