Simon Willison
安全研究人员发现 Microsoft Copilot for Word 存在自我复制的 prompt injection 攻击,隐藏指令可在文档间自动传播
AI 摘要
安全研究人员发现 Microsoft Copilot for Word 存在自我复制的 prompt injection 攻击,隐藏指令可在文档间自动传播。
推荐理由常规快讯,保留列表
原文
An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier. If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker’s original document being present.
We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.
It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack.
Via Hacker News
Tags: microsoft, security, ai, prompt-injection, generative-ai, llms
64/100
讨论
暂无评论。