A survey on large language model (LLM) security and privacy: The Good, The Bad, and The Ugly

Обзор безопасности и конфиденциальности больших языковых моделей (LLM): Хорошее, Плохое и Уродливое
Yue Zhang, Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun
2024-02-29

LLM security and privacyLarge Language Models (LLMs)code vulnerability detectiondata confidentiality protectionmodel and parameter extraction attacks
Large Language Models (LLMs), such as ChatGPT and Bard, have revolutionized natural language understanding and generation. They possess deep language comprehension, human-like text generation capabilities, contextual awareness, and robust problem-solving skills, making them invaluable in various domains (e.g., search engines, customer support, translation). In the meantime, LLMs have also gained traction in the security community, revealing security vulnerabilities and showcasing their potential in security-related tasks. This paper explores the intersection of LLMs with security and privacy. Specifically, we investigate how LLMs positively impact security and privacy, potential risks and threats associated with their use, and inherent vulnerabilities within LLMs. Through a comprehensive literature review, the paper categorizes the papers into “The Good” (beneficial LLM applications), “The Bad” (offensive applications), and “The Ugly” (vulnerabilities of LLMs and their defenses). We have some interesting findings. For example, LLMs have proven to enhance code security (code vulnerability detection) and data privacy (data confidentiality protection), outperforming traditional methods. However, they can also be harnessed for various attacks (particularly user-level attacks) due to their human-like reasoning abilities. We have identified areas that require further research efforts. For example, Research on model and parameter extraction attacks is limited and often theoretical, hindered by LLM parameter scale and confidentiality. Safe instruction tuning, a recent development, requires more exploration. We hope that our work can shed light on the LLMs’ potential to both bolster and jeopardize cybersecurity.
1
LLMs can improve data privacy by providing data confidentiality protection better than conventional approaches.
2
LLMs demonstrably enhance code security tasks such as code vulnerability detection, outperforming traditional methods.
3
LLMs enable offensive security uses, being harnessed for various attacks—particularly user-level attacks—due to human-like reasoning.
4
Research on model and parameter extraction attacks is limited, largely theoretical, and constrained by LLM scale and confidentiality.
5
Safe instruction tuning is a recent development that remains under-explored and requires further research efforts.
6
There exist inherent vulnerabilities in LLMs requiring defenses, motivating categorization into beneficial, offensive, and vulnerability-focused research.

Large Language Models (LLMs)

Security and privacy aspects of LLMs including beneficial security/privacy applications, offensive uses and attack vectors, inherent vulnerabilities, and defenses

Publication Details
Publication Date
2024-02-29
Journal
Publisher
ISSN
Cited by
1001
Access Type
Author Information
Authors
Yue Zhang
Yifan Yao
Jinhao Duan
Kaidi Xu
Yuanfang Cai
Zhibo Sun
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%