LATIDIA · Ciberseguridad
Cuidado con EviLLM: habilitar la inyección de vulnerabilidades a través de modelos de lenguaje grandes
arXiv: 2610.03857v1Tipo de anuncio: nuevo Resumen: Los avances en los modelos de lenguaje grande (LLM) han permitido la generación de código impulsado por IA a partir de especificaciones de lenguaje natural, introduciendo nuevas superficies de ataque para inyectar vulnerabilidades
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.03857v1 Announce Type: new Abstract: Advances in large language models (LLMs) have enabled AI-driven code generation from natural language specifications, introducing new attack surfaces for injecting vulnerabilities into software. Prior work has studied this problem only in benign settings where vulnerabilities are introduced inadvertently, or under unconventional threat models where the LLM itself is malicious (backdooring) or the user is the attacker (jailbreaking). In this paper, we study a more realistic threat model: a third-party adversary, with capabilities comparable to existing cybercriminals, compromises the AI code generation pipeline to deliberately introduce vulnerabilities. We call this the EviLLM attack. We have implemented two instances of EviLLM, each of which only requires