{"id":3433,"date":"2024-05-06T17:08:20","date_gmt":"2024-05-06T22:08:20","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/llms-malicious-code-injections-we-have-to-assume-its-coming-"},"modified":"2024-05-06T17:08:20","modified_gmt":"2024-05-06T22:08:20","slug":"llms-malicious-code-injections-we-have-to-assume-its-coming","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/06\/llms-malicious-code-injections-we-have-to-assume-its-coming\/","title":{"rendered":"LLMs &amp; Malicious Code Injections: &#8216;We Have to Assume It&#8217;s Coming&#8217;"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4c40e86e69bd4300\/6627bbf80558d7673b19a5a6\/LLM_Bakhtiar_Zein_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A rise in prompt injection engineering into <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/forget-deepfakes-or-phishing-prompt-injection-is-genai-s-biggest-problem\" rel=\"noopener\">large language models (LLMs)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> could emerge as a&nbsp;significant risk&nbsp;to organizations, an unintended consequence of AI discussed during a CISO roundtable discussion on Monday. The panel was held during&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.thepurplebook.club\/rsac-2024\" rel=\"noopener\">Purple Book Community Connect\u2013RSAC<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an event at this week&#8217;s RSA Conference in San Francisco.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u200dOne of the three panelists, Karthik Swarnam, CISO at ArmorCode, an application security operations platform provider, believes incidents arising from prompt injections in code are inevitable. &#8220;We haven&#8217;t seen it yet, but we have to assume that it is coming,&#8221; Swarnam tells Dark Reading.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Socially Engineered Text Alerts\">Socially Engineered Text Alerts<span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">&nbsp;<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">LLMs trained with malicious prompting can trigger code that pushes continuous text alerts with socially engineered messages that are typically less adversarial techniques. When a user unwittingly responds to the alert, the LLM could trigger nefarious actions such as unauthorized data sharing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Prompt engineering will be an area that companies should start to think about more and invest in,&#8221; Swarnam says. &#8220;They should train people in the very basics of it so that they know how to use it appropriately, which would yield positive results.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Swarnam, who has served as CISO of several large enterprises including Kroger and AT&amp;T, says despite concerns about the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/researchers-map-ai-threat-landscape-risks\" rel=\"noopener\">risks of using AI<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, most large organizations have begun embracing it for operations such as customer service and marketing. Even those that either prohibit AI or claim they&#8217;re not using it are probably unaware of down-low usage, also known as &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/first-step-in-ai-ml-security-is-finding-them\" rel=\"noopener\">shadow AI<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;All you have to do is go through your network logs and firewall logs, and you&#8217;ll find somebody is going to a third-party&nbsp;LLM&nbsp;or public LLM and doing all kinds of searches,&#8221;&nbsp;Swarnam says. &#8220;That reveals a lot of information. Companies and security teams are not naive, so they have realized that instead of saying &#8216;No&#8217;&nbsp;[to AI usage] they&#8217;re saying &#8216;Yes,&#8217;&nbsp;but establishing boundaries.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One area in which many companies have embraced AI is incident response and threat analytics. &#8220;Security information and event management is definitely getting disrupted with&nbsp;the use of&nbsp;this stuff,&#8221;&nbsp;Swarnam says. &#8220;It actually eliminates triaging at level one, and in a lot of cases at level two as well.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Adding AI to Application Development&nbsp;\">Adding AI to Application Development&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When using AI in application development tools, CISOs and CIOs should establish what type of coding assistance is practical for their organizations based on their capabilities and risk tolerance, Swarnam warns.&nbsp;&#8220;And don&#8217;t ignore the testing aspects,&#8221;&nbsp;he adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&nbsp;is also important for leaders to consistently track where their organizations are failing and reinforce&nbsp;it with training. &#8220;They should focus on things that they need, where they are making mistakes \u2014&nbsp;they are making&nbsp;constant challenges as they do development work or software development,&#8221; Swarnam says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/llms-malicious-code-injections-we-have-to-assume-its-coming-\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A rise in prompt injection engineering into large language models<\/p>\n","protected":false},"author":12,"featured_media":3434,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=1846%2C1043&ssl=1",1846,1043,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=640%2C362&ssl=1",640,362,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=640%2C362&ssl=1",640,362,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=1536%2C868&ssl=1",1536,868,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=1846%2C1043&ssl=1",1846,1043,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=1024%2C579&ssl=1",1024,579,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/llms-malicious-code-injections-we-have-to-assume-its-coming.jpg?fit=1846%2C1043&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3433"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3434"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}