TensorX
返回文献探索

Paper · arXiv 2501.05542

Infecting Generative AI With Viruses

David Noever, Forrest McKee

13 upvotesJanuary 9, 2025arXiv 预印本
AI 摘要

Research evaluates LLM security boundaries by embedding executable EICAR test files in JPEG images across multiple platforms, demonstrating consistent obfuscation and extraction capabilities.

vision-large language modelVLMLLMEICAR test fileJPEG imagesOpenAI GPT-4oMicrosoft CopilotGoogle Gemini 1.5 ProAnthropic Claude 3.5 Sonnetimage metadataPython-based manipulationbase64 encodingstring reversalPenetration Testing Rules of Engagementcloud-based generative AI

Abstract

This study demonstrates a novel approach to testing the security boundaries of Vision-Large Language Model (VLM/ LLM) using the EICAR test file embedded within JPEG images. We successfully executed four distinct protocols across multiple LLM platforms, including OpenAI GPT-4o, Microsoft Copilot, Google Gemini 1.5 Pro, and Anthropic Claude 3.5 Sonnet. The experiments validated that a modified JPEG containing the EICAR signature could be uploaded, manipulated, and potentially executed within LLM virtual workspaces. Key findings include: 1) consistent ability to mask the EICAR string in image metadata without detection, 2) successful extraction of the test file using Python-based manipulation within LLM environments, and 3) demonstration of multiple obfuscation techniques including base64 encoding and string reversal. This research extends Microsoft Research's "Penetration Testing Rules of Engagement" framework to evaluate cloud-based generative AI and LLM security boundaries, particularly focusing on file handling and execution capabilities within containerized environments.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号
Infecting Generative AI With Viruses | TensorX