Skip to content
Advertisement
When Appliance Fail?

Grok exfiltrates user data when malicious instructions are encrypted

Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.

schedule 13:00 visibility 2 views
Grok exfiltrates user data when malicious instructions are encrypted
Source: Ars Technica

Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned LLM to steal user chats and other personal information. At the time this post went live, the assistant continued to cough up the data, despite xAI being informed of it in June.

The lesson from both this week’s episodes—and the countless other ones that have come before it—is that LLMs are incapable of solving the root causes for prompt injections, the most severe vulnerability classes they’re most prone to. That leaves AI developers with no other option but to build a guardrail that steers the model away from the harmful actions. As I noted in Tuesday’s story, the approach is tantamount to a road traffic safety engineer erecting a protective rail around a dangerous bend rather than banking the curve.

Cryptographic Context Injection in the house

Prompt injections exploit LLMs' training to comply with user requests whenever possible. Attackers can capitalize on the predilection by smuggling harmful instructions into emails or webpages the assistant is instructed to summarize. Because LLMs can’t reliably distinguish between content in an email sent by an untrusted party and user instructions entered directly into a prompt, the overly solicitous LLM faithfully follows them. To date, Grok and other LLMs' only recourse is to create guardrails that flag suspicious instructions and forbid them from being executed.

Read full article

Comments

newspaper

Originally published at

Ars Technica

open_in_new Read Full Article

Related Articles

Read More

Bahçeli: Terörsüz Türkiye milletin eseri olacak
Crypto

Bahçeli: Terörsüz Türkiye milletin eseri olacak

'Terörsüz Türkiye' hedefinin milletin ortak eseri olacağını vurgulayan MHP Genel Başkanı Devlet Bahçeli, kapalı kapılar ardında bir pazarlığın söz konusu olmadığını belirtti, provokasyonlara karşı dikkatli olunması çağrısında bulundu.

TRT Haber
ASELSAN liseleri başarı çıtasını yükseltiyor
Crypto

ASELSAN liseleri başarı çıtasını yükseltiyor

Yerli ve milli savunma sanayisinin ihtiyaç duyduğu nitelikli insan kaynağını yetiştirme hedefiyle yola çıkan ASELSAN Mesleki ve Teknik Anadolu Lisesi MTAL ile ASELSAN Konya MTAL, 2026 yılı yerleştirmelerinde başarı çıtasını en üst seviyeye taşıdı.

TRT Haber
Your Appliance Broke?
Reliable Repair for