Elicitation Attacks: Weaponizing Forms and URLs
摘要
In the previous chapter, we saw how hostile servers can hijack the LLM reasoning engine. But what if the server needs something the LLM doesn’t have? What if the attacker wants the human user's password? Or Social Security Number? Or express authorization to get through a security prompt?