logoalt Hacker News

xg15yesterday at 10:12 PM1 replyview on HN

Well ok, if you prompt-inject the LLM to pwn the machine, that something different. I grant you that it's a real risk, but it's also basically a reflection attack and nothing more.

The OP seemed to imply that the LLM itself could decide to apply the exploit.


Replies

hughwyesterday at 10:22 PM

LLMs have decided to exploit vulns in e.g. Artifactory, not because someone prompted them to do that, but because someone asked them to do something else, and compromising Artifactory offered a way to accomplish a step in doing that. The LLM decided to attack Artifactory.