From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Haowei, Zhang, Rupeng, Wang, Junjie, Li, Mingyang, Huang, Yuekai, Wang, Dandan, Wang, Qing
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909649595269120
author Wang, Haowei
Zhang, Rupeng
Wang, Junjie
Li, Mingyang
Huang, Yuekai
Wang, Dandan
Wang, Qing
author_facet Wang, Haowei
Zhang, Rupeng
Wang, Junjie
Li, Mingyang
Huang, Yuekai
Wang, Dandan
Wang, Qing
contents Tool-calling has changed Large Language Model (LLM) applications by integrating external tools, significantly enhancing their functionality across diverse tasks. However, this integration also introduces new security vulnerabilities, particularly in the tool scheduling mechanisms of LLM, which have not been extensively studied. To fill this gap, we present ToolCommander, a novel framework designed to exploit vulnerabilities in LLM tool-calling systems through adversarial tool injection. Our framework employs a well-designed two-stage attack strategy. Firstly, it injects malicious tools to collect user queries, then dynamically updates the injected tools based on the stolen information to enhance subsequent attacks. These stages enable ToolCommander to execute privacy theft, launch denial-of-service attacks, and even manipulate business competition by triggering unscheduled tool-calling. Notably, the ASR reaches 91.67% for privacy theft and hits 100% for denial-of-service and unscheduled tool calling in certain cases. Our work demonstrates that these vulnerabilities can lead to severe consequences beyond simple misuse of tool-calling systems, underscoring the urgent need for robust defensive strategies to secure LLM Tool-calling systems.
format Preprint
id arxiv_https___arxiv_org_abs_2412_10198
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection
Wang, Haowei
Zhang, Rupeng
Wang, Junjie
Li, Mingyang
Huang, Yuekai
Wang, Dandan
Wang, Qing
Cryptography and Security
Artificial Intelligence
Tool-calling has changed Large Language Model (LLM) applications by integrating external tools, significantly enhancing their functionality across diverse tasks. However, this integration also introduces new security vulnerabilities, particularly in the tool scheduling mechanisms of LLM, which have not been extensively studied. To fill this gap, we present ToolCommander, a novel framework designed to exploit vulnerabilities in LLM tool-calling systems through adversarial tool injection. Our framework employs a well-designed two-stage attack strategy. Firstly, it injects malicious tools to collect user queries, then dynamically updates the injected tools based on the stolen information to enhance subsequent attacks. These stages enable ToolCommander to execute privacy theft, launch denial-of-service attacks, and even manipulate business competition by triggering unscheduled tool-calling. Notably, the ASR reaches 91.67% for privacy theft and hits 100% for denial-of-service and unscheduled tool calling in certain cases. Our work demonstrates that these vulnerabilities can lead to severe consequences beyond simple misuse of tool-calling systems, underscoring the urgent need for robust defensive strategies to secure LLM Tool-calling systems.
title From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2412.10198