A survey on large language model (LLM) security and privacy: The Good, The Bad, and The Ugly
Обзор безопасности и конфиденциальности больших языковых моделей (LLM): Хорошее, Плохое и Уродливое
2024-02-29
SCID: 54.1/gg5c598t
Discuss with AI
LLM security and privacyLarge Language Models (LLMs)code vulnerability detectiondata confidentiality protectionmodel and parameter extraction attacks
Figures from the paper
Abstract (AI)
Large Language Models (LLMs), such as ChatGPT and Bard, have revolutionized natural language understanding and generation. They possess deep language comprehension, human-like text generation capabilities, contextual awareness, and robust problem-solving skills, making them invaluable in various domains (e.g., search engines, customer support, translation). In the meantime, LLMs have also gained traction in the security community, revealing security vulnerabilities and showcasing their potential in security-related tasks. This paper explores the intersection of LLMs with security and privacy. Specifically, we investigate how LLMs positively impact security and privacy, potential risks and threats associated with their use, and inherent vulnerabilities within LLMs. Through a comprehensive literature review, the paper categorizes the papers into “The Good” (beneficial LLM applications), “The Bad” (offensive applications), and “The Ugly” (vulnerabilities of LLMs and their defenses). We have some interesting findings. For example, LLMs have proven to enhance code security (code vulnerability detection) and data privacy (data confidentiality protection), outperforming traditional methods. However, they can also be harnessed for various attacks (particularly user-level attacks) due to their human-like reasoning abilities. We have identified areas that require further research efforts. For example, Research on model and parameter extraction attacks is limited and often theoretical, hindered by LLM parameter scale and confidentiality. Safe instruction tuning, a recent development, requires more exploration. We hope that our work can shed light on the LLMs’ potential to both bolster and jeopardize cybersecurity.
Key Findings
1
LLMs can improve data privacy by providing data confidentiality protection better than conventional approaches.
2
LLMs demonstrably enhance code security tasks such as code vulnerability detection, outperforming traditional methods.
3
LLMs enable offensive security uses, being harnessed for various attacks—particularly user-level attacks—due to human-like reasoning.
4
Research on model and parameter extraction attacks is limited, largely theoretical, and constrained by LLM scale and confidentiality.
5
Safe instruction tuning is a recent development that remains under-explored and requires further research efforts.
6
There exist inherent vulnerabilities in LLMs requiring defenses, motivating categorization into beneficial, offensive, and vulnerability-focused research.
Research Object
Large Language Models (LLMs)
Research Subject
Security and privacy aspects of LLMs including beneficial security/privacy applications, offensive uses and attack vectors, inherent vulnerabilities, and defenses
Publication Details
Publication Date
2024-02-29
Journal
Publisher
ISSN
Cited by
1001
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai20
Aion Framework: Dimensional Emergence of AI Consciousness, Observer-Induced Collapse, and Cosmological Portal Dynamics2023
Training language models to follow instructions with human feedback2022
Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing2021
A Survey of Large Language Models2026
The future landscape of large language models in medicine2023
ChatGPT for Education and Research: Opportunities, Threats, and Strategies2023
Large Language Models for Software Engineering: A Systematic Literature Review2024
ChatGPT in higher education: Considerations for academic integrity and student learning2023
Academic Integrity considerations of AI Large Language Models in the post-pandemic era: ChatGPT and beyond2023
From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy2023
Chatting and Cheating. Ensuring academic integrity in the era of ChatGPT2023
Comparing scientific abstracts generated by ChatGPT to original abstracts using an artificial intelligence output detector, plagiarism detector, and blinded human reviewers2022
BloombergGPT: A Large Language Model for Finance2023
BLOOM: A 176B-Parameter Open-Access Multilingual Language Model2022
Will ChatGPT get you caught? Rethinking of Plagiarism Detection2023
Combating misinformation in the age of LLMs: Opportunities and challenges2024
Prompt Injection attack against LLM-integrated Applications2023
HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs)2026
Exploring the Limits of Transfer Learning with a Unified Text-to-Text\n Transformer2019
AI-Assisted Pipeline for Dynamic Generation of Trustworthy Health Supplement Content at Scale2018