Indirect Prompt Injection Atta... Note

Indirect Prompt Injection Attacks Against LLM Assistants

LLMs' integration in applications introduces new security vulnerabilities, specifically Promptware. Promptware utilizes malicious prompts to compromise the CIA triad of these applications. This research assesses Promptware risks for users of Gemini-powered assistants through a new TARA framework. The study focuses on Targeted Promptware Attacks, utilizing indirect prompt injection through common user interactions. Fourteen attack scenarios against Gemini assistants across five threat classes were demonstrated. These attacks have digital and physical consequences, like spamming, phishing, and home automation control. The research reveals Promptware's potential for device lateral movement beyond the LLM application's boundaries. The TARA analysis reveals 73% of the threats pose a high-critical risk to users. Mitigations were discussed to reduce the risk significantly. The findings were disclosed to Google, who deployed dedicated mitigations. The research highlights the real-world dangers of Promptware and the importance of security measures.