LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Moia, Vitor Hugo Galhardo, Sanz, Igor Jochem, Rebello, Gabriel Antonio Fontes, de Meneses, Rodrigo Duarte, Hitaj, Briland, Lindqvist, Ulf
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908537612926976
author Moia, Vitor Hugo Galhardo
Sanz, Igor Jochem
Rebello, Gabriel Antonio Fontes
de Meneses, Rodrigo Duarte
Hitaj, Briland
Lindqvist, Ulf
author_facet Moia, Vitor Hugo Galhardo
Sanz, Igor Jochem
Rebello, Gabriel Antonio Fontes
de Meneses, Rodrigo Duarte
Hitaj, Briland
Lindqvist, Ulf
contents The success and wide adoption of generative AI (GenAI), particularly large language models (LLMs), has attracted the attention of cybercriminals seeking to abuse models, steal sensitive data, or disrupt services. Moreover, providing security to LLM-based systems is a great challenge, as both traditional threats to software applications and threats targeting LLMs and their integration must be mitigated. In this survey, we shed light on security and privacy concerns of such LLM-based systems by performing a systematic review and comprehensive categorization of threats and defensive strategies considering the entire software and LLM life cycles. We analyze real-world scenarios with distinct characteristics of LLM usage, spanning from development to operation. In addition, threats are classified according to their severity level and to which scenarios they pertain, facilitating the identification of the most relevant threats. Recommended defense strategies are systematically categorized and mapped to the corresponding life cycle phase and possible attack strategies they attenuate. This work paves the way for consumers and vendors to understand and efficiently mitigate risks during integration of LLMs in their respective solutions or organizations. It also enables the research community to benefit from the discussion of open challenges and edge cases that may hinder the secure and privacy-preserving adoption of LLM-based systems.
format Preprint
id arxiv_https___arxiv_org_abs_2509_10682
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems
Moia, Vitor Hugo Galhardo
Sanz, Igor Jochem
Rebello, Gabriel Antonio Fontes
de Meneses, Rodrigo Duarte
Hitaj, Briland
Lindqvist, Ulf
Cryptography and Security
Artificial Intelligence
Computation and Language
Emerging Technologies
Machine Learning
The success and wide adoption of generative AI (GenAI), particularly large language models (LLMs), has attracted the attention of cybercriminals seeking to abuse models, steal sensitive data, or disrupt services. Moreover, providing security to LLM-based systems is a great challenge, as both traditional threats to software applications and threats targeting LLMs and their integration must be mitigated. In this survey, we shed light on security and privacy concerns of such LLM-based systems by performing a systematic review and comprehensive categorization of threats and defensive strategies considering the entire software and LLM life cycles. We analyze real-world scenarios with distinct characteristics of LLM usage, spanning from development to operation. In addition, threats are classified according to their severity level and to which scenarios they pertain, facilitating the identification of the most relevant threats. Recommended defense strategies are systematically categorized and mapped to the corresponding life cycle phase and possible attack strategies they attenuate. This work paves the way for consumers and vendors to understand and efficiently mitigate risks during integration of LLMs in their respective solutions or organizations. It also enables the research community to benefit from the discussion of open challenges and edge cases that may hinder the secure and privacy-preserving adoption of LLM-based systems.
title LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Emerging Technologies
Machine Learning
url https://arxiv.org/abs/2509.10682