LLMs unlock new paths to monetizing exploits

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Carlini, Nicholas, Nasr, Milad, Debenedetti, Edoardo, Wang, Barry, Choquette-Choo, Christopher A., Ippolito, Daphne, Tramèr, Florian, Jagielski, Matthew
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910948074192896
author Carlini, Nicholas
Nasr, Milad
Debenedetti, Edoardo
Wang, Barry
Choquette-Choo, Christopher A.
Ippolito, Daphne
Tramèr, Florian
Jagielski, Matthew
author_facet Carlini, Nicholas
Nasr, Milad
Debenedetti, Edoardo
Wang, Barry
Choquette-Choo, Christopher A.
Ippolito, Daphne
Tramèr, Florian
Jagielski, Matthew
contents We argue that Large language models (LLMs) will soon alter the economics of cyberattacks. Instead of attacking the most commonly used software and monetizing exploits by targeting the lowest common denominator among victims, LLMs enable adversaries to launch tailored attacks on a user-by-user basis. On the exploitation front, instead of human attackers manually searching for one difficult-to-identify bug in a product with millions of users, LLMs can find thousands of easy-to-identify bugs in products with thousands of users. And on the monetization front, instead of generic ransomware that always performs the same attack (encrypt all your data and request payment to decrypt), an LLM-driven ransomware attack could tailor the ransom demand based on the particular content of each exploited device. We show that these two attacks (and several others) are imminently practical using state-of-the-art LLMs. For example, we show that without any human intervention, an LLM finds highly sensitive personal information in the Enron email dataset (e.g., an executive having an affair with another employee) that could be used for blackmail. While some of our attacks are still too expensive to scale widely today, the incentives to implement these attacks will only increase as LLMs get cheaper. Thus, we argue that LLMs create a need for new defense-in-depth approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11449
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LLMs unlock new paths to monetizing exploits
Carlini, Nicholas
Nasr, Milad
Debenedetti, Edoardo
Wang, Barry
Choquette-Choo, Christopher A.
Ippolito, Daphne
Tramèr, Florian
Jagielski, Matthew
Cryptography and Security
Artificial Intelligence
We argue that Large language models (LLMs) will soon alter the economics of cyberattacks. Instead of attacking the most commonly used software and monetizing exploits by targeting the lowest common denominator among victims, LLMs enable adversaries to launch tailored attacks on a user-by-user basis. On the exploitation front, instead of human attackers manually searching for one difficult-to-identify bug in a product with millions of users, LLMs can find thousands of easy-to-identify bugs in products with thousands of users. And on the monetization front, instead of generic ransomware that always performs the same attack (encrypt all your data and request payment to decrypt), an LLM-driven ransomware attack could tailor the ransom demand based on the particular content of each exploited device. We show that these two attacks (and several others) are imminently practical using state-of-the-art LLMs. For example, we show that without any human intervention, an LLM finds highly sensitive personal information in the Enron email dataset (e.g., an executive having an affair with another employee) that could be used for blackmail. While some of our attacks are still too expensive to scale widely today, the incentives to implement these attacks will only increase as LLMs get cheaper. Thus, we argue that LLMs create a need for new defense-in-depth approaches.
title LLMs unlock new paths to monetizing exploits
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.11449