4 ms·
Last week I spoke at the Chaos Communication Congress about real-world exploits I discovered in LLM apps and how vendors fixed issues over the course of last ye
by wunderwuzzi23 3y ago
Last week I spoke at the Chaos Communication Congress about real-world exploits I discovered in LLM apps and how vendors fixed issues over the course of last year (basically impacting all major vendors).
From stealing emails and source code, to remote code execution and of course scamming users there are a lot of threats to consider and a lot that can go (and as these exploits and fixes show, already has gone) wrong when building Chatbots and LLM apps.
If you are curious, a recording of the talk is here: https://www.youtube.com/watch?v=qyTSOSDEC5M https://www.youtube.com/watch?v=qyTSOSDEC5M
- nradov 3y agoNone of those threats have any particular relationship to chatbots or LLMs. If you expose sensitive data on untrusted systems then it will eventually be breached. Ho hum.
- wunderwuzzi23 3y agoGiving LLMs more agency/integrations is what most companies are working on, and prompt injection is specifically an LLM AppSec problem.
- hm-nah 3y agoI watched your awesome presentation. I don’t recall the topic of sandboxing code execution. AutoGPT has the option to execute code in a Docker Container. Curious what you think of the scenario where an LLM is “tricked” to execute malicious code in a trusted env.