Are Your LLM-based Text-to-SQL Models Secure? Exploring SQL Injection via Backdoor Attacks
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Lin, Meiyu, Zhang, Haichuan, Lao, Jiale, Li, Renyuan, Zhou, Yuanchun, Yang, Carl, Cao, Yang, Tang, Mingjie |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Attack as Defense: Run-time Backdoor Implantation for Image Content Protection
von: Zhang, Haichuan, et al.
Veröffentlicht: (2024)
von: Zhang, Haichuan, et al.
Veröffentlicht: (2024)
Can You Trust the Vectors in Your Vector Database? Black-Hole Attack from Embedding Space Defects
von: Li, Hanxi, et al.
Veröffentlicht: (2026)
von: Li, Hanxi, et al.
Veröffentlicht: (2026)
On the Security Vulnerabilities of Text-to-SQL Models
von: Peng, Xutan, et al.
Veröffentlicht: (2022)
von: Peng, Xutan, et al.
Veröffentlicht: (2022)
FHE-SQL: Fully Homomorphic Encrypted SQL Database
von: Tseng, Po-Yu, et al.
Veröffentlicht: (2025)
von: Tseng, Po-Yu, et al.
Veröffentlicht: (2025)
RADAR: Exposing Unlogged NoSQL Operations
von: Nissan, Mahfuzul I., et al.
Veröffentlicht: (2026)
von: Nissan, Mahfuzul I., et al.
Veröffentlicht: (2026)
From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?
von: Pedro, Rodrigo, et al.
Veröffentlicht: (2023)
von: Pedro, Rodrigo, et al.
Veröffentlicht: (2023)
FuzzySQL: Uncovering Hidden Vulnerabilities in DBMS Special Features with LLM-Driven Fuzzing
von: Chen, Yongxin, et al.
Veröffentlicht: (2026)
von: Chen, Yongxin, et al.
Veröffentlicht: (2026)
DePLOI: Applying NL2SQL to Synthesize and Audit Database Access Control
von: Subramaniam, Pranav, et al.
Veröffentlicht: (2024)
von: Subramaniam, Pranav, et al.
Veröffentlicht: (2024)
PoneglyphDB: Efficient Non-interactive Zero-Knowledge Proofs for Arbitrary SQL-Query Verification
von: Gu, Binbin, et al.
Veröffentlicht: (2024)
von: Gu, Binbin, et al.
Veröffentlicht: (2024)
MemTraceDB: Reconstructing MySQL User Activity Using ActiviTimeTrace Algorithm
von: Nissan, Mahfuzul I.
Veröffentlicht: (2025)
von: Nissan, Mahfuzul I.
Veröffentlicht: (2025)
Leveraging large language models for SQL behavior-based database intrusion detection
von: Shlezinger, Meital, et al.
Veröffentlicht: (2025)
von: Shlezinger, Meital, et al.
Veröffentlicht: (2025)
Blockchain-based vs. SQL Database Systems for Digital Twin Evidence Management: A Comparative Forensic Analysis
von: Franken, Boyd, et al.
Veröffentlicht: (2025)
von: Franken, Boyd, et al.
Veröffentlicht: (2025)
DPSQL+: A Differentially Private SQL Library with a Minimum Frequency Rule
von: Matsumoto, Tomoya, et al.
Veröffentlicht: (2026)
von: Matsumoto, Tomoya, et al.
Veröffentlicht: (2026)
Algorithmic Complexity Attacks on Dynamic Learned Indexes
von: Yang, Rui, et al.
Veröffentlicht: (2024)
von: Yang, Rui, et al.
Veröffentlicht: (2024)
Enabling Efficient Attack Investigation via Human-in-the-Loop Security Analysis
von: Tsegai, Saimon Amanuel, et al.
Veröffentlicht: (2022)
von: Tsegai, Saimon Amanuel, et al.
Veröffentlicht: (2022)
MaskSQL: Safeguarding Privacy for LLM-Based Text-to-SQL via Abstraction
von: Abedini, Sepideh, et al.
Veröffentlicht: (2025)
von: Abedini, Sepideh, et al.
Veröffentlicht: (2025)
ProGQL: A Provenance Graph Query System for Cyber Attack Investigation
von: Shao, Fei, et al.
Veröffentlicht: (2025)
von: Shao, Fei, et al.
Veröffentlicht: (2025)
GPM: The Gaussian Pancake Mechanism for Planting Undetectable Backdoors in Differential Privacy
von: Sun, Haochen, et al.
Veröffentlicht: (2025)
von: Sun, Haochen, et al.
Veröffentlicht: (2025)
Defense against Poisoning Attacks under Shuffle-DP
von: Wang, Siyi, et al.
Veröffentlicht: (2026)
von: Wang, Siyi, et al.
Veröffentlicht: (2026)
Adversarial SQL Injection Generation with LLM-Based Architectures
von: Karakoc, Ali, et al.
Veröffentlicht: (2026)
von: Karakoc, Ali, et al.
Veröffentlicht: (2026)
VulGD: A LLM-Powered Dynamic Open-Access Vulnerability Graph Database
von: Do, Luat, et al.
Veröffentlicht: (2026)
von: Do, Luat, et al.
Veröffentlicht: (2026)
SQL Injection Jailbreak: A Structural Disaster of Large Language Models
von: Zhao, Jiawei, et al.
Veröffentlicht: (2024)
von: Zhao, Jiawei, et al.
Veröffentlicht: (2024)
Secure Query Processing with Linear Complexity
von: Luo, Qiyao, et al.
Veröffentlicht: (2024)
von: Luo, Qiyao, et al.
Veröffentlicht: (2024)
PACE: Poisoning Attacks on Learned Cardinality Estimation
von: Zhang, Jintao, et al.
Veröffentlicht: (2024)
von: Zhang, Jintao, et al.
Veröffentlicht: (2024)
Security in IS and social engineering -- an overview and state of the art
von: Sèdes, Florence
Veröffentlicht: (2024)
von: Sèdes, Florence
Veröffentlicht: (2024)
SPECIAL: Synopsis Assisted Secure Collaborative Analytics
von: Wang, Chenghong, et al.
Veröffentlicht: (2024)
von: Wang, Chenghong, et al.
Veröffentlicht: (2024)
Data Poisoning Attacks to Local Differential Privacy Protocols for Graphs
von: He, Xi, et al.
Veröffentlicht: (2024)
von: He, Xi, et al.
Veröffentlicht: (2024)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
von: Yang, Guan-Yan, et al.
Veröffentlicht: (2025)
von: Yang, Guan-Yan, et al.
Veröffentlicht: (2025)
ORQ: Complex Analytics on Private Data with Strong Security Guarantees
von: Baum, Eli, et al.
Veröffentlicht: (2025)
von: Baum, Eli, et al.
Veröffentlicht: (2025)
Interactive Trimming against Evasive Online Data Manipulation Attacks: A Game-Theoretic Approach
von: Fu, Yue, et al.
Veröffentlicht: (2024)
von: Fu, Yue, et al.
Veröffentlicht: (2024)
Reflex: Faster Secure Collaborative Analytics via Controlled Intermediate Result Size Disclosure
von: Gu, Long, et al.
Veröffentlicht: (2025)
von: Gu, Long, et al.
Veröffentlicht: (2025)
FRAG: Toward Federated Vector Database Management for Collaborative and Secure Retrieval-Augmented Generation
von: Zhao, Dongfang
Veröffentlicht: (2024)
von: Zhao, Dongfang
Veröffentlicht: (2024)
Femur: A Flexible Framework for Fast and Secure Querying from Public Key-Value Store
von: Zhang, Jiaoyi, et al.
Veröffentlicht: (2025)
von: Zhang, Jiaoyi, et al.
Veröffentlicht: (2025)
Towards Privacy-Preserving Range Queries with Secure Learned Spatial Index over Encrypted Data
von: Wang, Zuan, et al.
Veröffentlicht: (2025)
von: Wang, Zuan, et al.
Veröffentlicht: (2025)
Enhancing SQL Injection Detection and Prevention Using Generative Models
von: Dasari, Naga Sai, et al.
Veröffentlicht: (2025)
von: Dasari, Naga Sai, et al.
Veröffentlicht: (2025)
HexaMorphHash HMH- Homomorphic Hashing for Secure and Efficient Cryptographic Operations in Data Integrity Verification
von: Das, Krishnendu
Veröffentlicht: (2025)
von: Das, Krishnendu
Veröffentlicht: (2025)
Implementing a Scalable, Redeployable and Multitiered Repository for FAIR and Secure Scientific Data Sharing: The BIG-MAP Archive
von: Granata, Valeria, et al.
Veröffentlicht: (2025)
von: Granata, Valeria, et al.
Veröffentlicht: (2025)
DP-S4S: Accurate and Scalable Select-Join-Aggregate Query Processing with User-Level Differential Privacy
von: Qiu, Yuan, et al.
Veröffentlicht: (2026)
von: Qiu, Yuan, et al.
Veröffentlicht: (2026)
UltraClean: A Simple Framework to Train Robust Neural Networks against Backdoor Attacks
von: Zhao, Bingyin, et al.
Veröffentlicht: (2023)
von: Zhao, Bingyin, et al.
Veröffentlicht: (2023)
AdvSQLi: Generating Adversarial SQL Injections against Real-world WAF-as-a-service
von: Qu, Zhenqing, et al.
Veröffentlicht: (2024)
von: Qu, Zhenqing, et al.
Veröffentlicht: (2024)
Ähnliche Einträge
-
Attack as Defense: Run-time Backdoor Implantation for Image Content Protection
von: Zhang, Haichuan, et al.
Veröffentlicht: (2024) -
Can You Trust the Vectors in Your Vector Database? Black-Hole Attack from Embedding Space Defects
von: Li, Hanxi, et al.
Veröffentlicht: (2026) -
On the Security Vulnerabilities of Text-to-SQL Models
von: Peng, Xutan, et al.
Veröffentlicht: (2022) -
FHE-SQL: Fully Homomorphic Encrypted SQL Database
von: Tseng, Po-Yu, et al.
Veröffentlicht: (2025) -
RADAR: Exposing Unlogged NoSQL Operations
von: Nissan, Mahfuzul I., et al.
Veröffentlicht: (2026)