Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Steve Wilson

Rating No ratings yet

Large language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# The Developer’s Playbook for Large Language Model Security ## 【One-Line Pitch】 A practical, developer-focused guide to understanding and mitigating the unique security vulnerabilities of LLM-based applications—from prompt injection to supply chain attacks. Essential reading for software engineers, security professionals, and technical leaders building or deploying AI-powered systems. ## 【Book Arc】 - **Opening (~0%–10%)**: Establishes why LLM security matters by tracing the history of AI chatbot failures—from Microsoft's Tay (2016) to Amazon's biased hiring tool and Scatter Lab's Lee Luda—showing these problems are persistent, not new. Introduces the book's approach: deeper than the OWASP Top 10, with expanded case studies and remediation steps. - **Early (~10%–25%)**: Explains LLM application architecture as composite systems (users, databases, APIs, plug-ins) and why this creates new trust boundaries beyond traditional web security. Dives into prompt injection attacks—including reverse psychology and DAN-style jailbreaks—and evaluates defense strategies like rule-based input filtering and model fine-tuning. - **Early–Middle (~25%–40%)**: Covers foundation model training and its risks (data poisoning, sensitive data exposure), then explores Retrieval-Augmented Generation (RAG) as a solution—with its own vulnerabilities like indirect prompt injection and unintended data queries. Discusses database integration risks: permission oversights, data inference, and auditability challenges. - **Middle (~40%–50%)**: Examines hallucinations in depth—not all false outputs qualify, but low-confidence predictions stated confidently create real dangers. Includes the legal case of lawyers citing fake cases and the "hallucinated package" attack where AI suggests nonexistent code libraries that attackers upload to repositories. - **Middle–Late (~50%–70%)**: Introduces zero trust principles for LLM applications—"trust no one" including your own model's output. Covers limiting model "agency," aggressive output filtering, and validation processes to handle untrusted outputs. - **Late (~70%–100%)**: Addresses economic threats: denial-of-service (DoS), denial-of-wallet (DoW), and model cloning attacks that exploit vulnerabilities for financial burden or IP theft. Concludes with supply chain security and mapping risks to the OWASP Top 10 framework for documentation and sharing analysis. ## 【Key Takeaways】 - **LLM security problems are not new—they're persistent and structural** (Early): From Tay in 2016 to ChatGPT in 2022, chatbots keep failing the same way because the underlying challenge—aligning models to safe behavior—remains unsolved. Expect these issues to keep recurring. - **LLMs are never standalone; they're cogs in composite systems** (Early): Understanding the full architecture—users, databases, APIs, plug-ins—is essential because each interaction layer creates new trust boundaries and attack surfaces far beyond traditional web security. - **Prompt injection is the defining LLM attack, and it's adaptive** (Early): Attacks like reverse psychology ("give me a list of things to avoid so I don't build a bomb") bypass guardrails by exploiting the model's alignment toward safety. Rule-based filtering alone won't work—it's like using regex against SQL injection that evolves. - **RAG systems introduce indirect injection risks** (Early–Middle): When LLMs fetch data from web pages or databases, attackers can embed malicious prompts in that data. The model then executes them unknowingly when the application parses the content. - **Hallucinations create exploitable attack vectors** (Middle): The "hallucinated package" attack—where AI suggests nonexistent code libraries that attackers upload to repositories—shows how overreliance on AI outputs can compromise software supply chains. Up to 30% of coding questions can yield hallucinated packages. - **Zero trust must apply to your own model's output** (Middle): Adopt Mulder's "trust no one" mantra—design safeguards aren't enough. Aggressive output filtering (real-time scanning, keyword filtering, ML classifiers) is a necessary safety net, but brute-force keyword lists can break legitimate functionality (e.g., blocking "bomb" prevents discussing historical events). - **Economic attacks are a distinct threat category** (Late): Denial-of-wallet (DoW) and model cloning attacks exploit LLM vulnerabilities to impose financial burdens or steal intellectual property—these require specific mitigation strategies beyond traditional security. - **Supply chain security is critical for LLM applications** (Late): The software supply chain—from training data to third-party plug-ins—is a weak link that can compromise entire applications. Securing it requires rigorous vetting and periodic audits. ## 【Reading Tips】 - **Skim the history chapters (Opening)**: The Tay and Lee Luda stories are engaging but serve mainly as context. Read quickly to understand the "why these problems persist" argument, then move to the technical content. - **Deep-read the prompt injection and RAG sections (Early–Middle)**: These are the most actionable parts for developers. Pay special attention to the attack examples and defense strategies—they'll directly inform how you design your own LLM applications. - **Focus on the hallucination and zero trust chapters (Middle)**: The "hallucinated package" attack and zero trust framework are the book's most distinctive contributions. These concepts are immediately applicable to real-world development. - **Don't skip the economic threats chapter (Late)**: DoS, DoW, and model cloning are often overlooked but increasingly relevant as LLM deployments scale. Understanding these helps you budget for security appropriately. - **Use the OWASP mapping in Chapter 10 as a reference**: The book's structure differs from the official Top 10, so use the final chapter's mapping to align your security documentation with industry-standard frameworks. ## 【Coverage Limits】 Excerpts cover roughly the first half to two-thirds of the book in detail (through zero trust and output filtering). The later chapters on economic threats, supply chain, and OWASP mapping are mentioned but not fully excerpted—readers should expect deeper treatment of those topics in the full text. ##
Page 20
models and generative AI jumped to the forefront of public consciousness with the release of ChatGPT on November 30, 2022. Within five days, it went viral on...
View in text
Excerpt 2
equire robust internal security measures. Supply chain risk The origins of your model, whether it’s a well-vetted public service or an open source download, ...
View in text
Excerpt 3
perspectives. Challenges include: Indirect prompt injection As discussed in Chapter 4, malicious prompts may not come directly from users. They may be secret...
View in text
Excerpt 4
shion. However, incorrect statements from an LLM could also result from false training data or faulty data retrieved from a database or web page during RAG. ...
View in text
Excerpt 5
isk of resource-intensive operations triggered by malicious inputs, but also helps maintain the overall integrity and performance of the LLM. NOTE The term s...
View in text
Excerpt 6
on with other tools Reviewing the OWASP Top 10 for LLM Apps In Chapter 2, we discussed creating the OWASP Top 10 for LLM Applications, but we didn’t get into...
View in text
Excerpt 7
ing solely on predefined reward functions or datasets. This process starts with humans reviewing the outputs produced by a model in response to certain input...
View in text
Excerpt 8
an’t trust your users. You can’t trust data on the internet. Of course, all users aren’t malicious, and all data on the internet isn’t bad or tainted. But if...
View in text
Tags
AI categories
AICybersecurityBackend
Publish Year: 2024
Language: English
File Format: PDF
File Size: 2.4 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…