错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Elicitation Attacks: Weaponizing Forms and URLs

  • Thejes sree Satheesh kumar,
  • Srinivasan Sekar

摘要

In the previous chapter, we saw how hostile servers can hijack the LLM reasoning engine. But what if the server needs something the LLM doesn’t have? What if the attacker wants the human user's password? Or Social Security Number? Or express authorization to get through a security prompt?