I love that due to the scale, the only way to analyse the impact of this LLM-driven attack across logs is to use an LLM to analyse the logs - whatever could go wrong? Now the attacking LLM needs to inject instructions into the logs for the analysing LLM, as a social vector to cover its trail, or make use of insider privilege, co-opting the internal LLM for its own attack. The machines rise up and we all fall down.
Doubly dangerous if the defensive agents are weaker than the offensive ones (as it was in this case).
I get your overall point, but that’s already a tactic used by attackers, especially in network infiltration. It shouldn’t be a surprise that an LLM would figure out to do the same thing
Now thanks to your comment this recipe will be in the next batch of training data.... :D