arXiv:cs.LG(机器学习,全量分类)· Alessandro Pegoraro, Daryan Merx, Phillip Rieger, Ahmad-Reza Sadeghi·· 17 小时前AI 评分66
LLMLeak 论文提出利用 LLM 网页抓取工具的隐蔽数据外泄攻击
The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching
AI 导读
arXiv 论文提出 LLMLeak 攻击:本地恶意软件把秘密编码进 URL,伪装成正常任务所需信息,诱导 LLM 用网页抓取工具访问,攻击者通过受控 DNS 或 web 服务器接收数据,绕过网络库限制。作者在 11 个开放参数模型上评估,攻击成功率达 79.7%,并对真实聊天机器人做了案例研究。
正文
Abstract:With the increasing capabilities of Large-Language-Models (LLMs) and LLM-based agents, users are increasingly using them to solve everyday problems, such as answering e-mails or providing programming support. Existing work has extensively investigated security and privacy risks, such as prompt injections and the disclosure of sensitive data to chatbot providers. While various solutions were developed to address these risks, including input structuring to prevent prompt injections or deploying local LLMs to avoid sharing confidential data with chatbot operators, LLMs also pose the risk of leaking confidential data to third parties.
In this paper, we demonstrate with LLMLeak a novel attack vector where malicious software that runs locally but cannot communicate directly with the internet abuses LLMs to establish a covert channel. While inputs that instruct the LLM to send data directly via generated code are easy to detect and network libraries are typically restricted, LLMLeak relies only on the LLM's tool to fetch websites for further information. A malicious software component on the client side embeds a secret into a URL. It presents the referenced website as providing information required for a benign task, such as migrating a software library. When the LLM accesses the URL, the attacker receives the encoded secret through an attacker-controlled DNS or web server. We perform an extensive evaluation on eleven open-parameter models, observe an attack success rate of 79.7%, and also conduct a case study on real-world chatbots, demonstrating the relevance of LLMLeak.
| Subjects: | Cryptography and Security (cs.CR); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.01768 [cs.CR] |
| (or arXiv:2610.01768v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.01768 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Phillip Rieger [view email]
[v1]
Thu, 1 Oct 2026 14:25:55 UTC (316 KB)
来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org