Desk/2023-W08

Week of Feb 20–26, 2023

1 records0 status changes on new evidence0 new findings

Attacks & incidents

Feb 23, 2023
Researchers define indirect prompt injection against LLM-integrated apps including Bing Chat
AttackPaperCISPA Helmholtz Center for Information Security, sequire technology

Greshake et al. describe indirect prompt injection, where instructions planted in data an LLM application retrieves are treated as commands. The paper demonstrates the attack class against Bing's GPT-4 powered chat, code-completion engines, and synthetic GPT-4 applications, and catalogs impacts including data theft, worming, and unauthorized API calls.