AltaySec · ATLAS 2026.07
AML.T0086

Exfiltration via AI Agent Tool Invocation

Bu tekniğin yerleşik Türkçe adı henüz terminoloji kanonuna eklenmedi; İngilizce adı gösteriliyor.

C · Açıklama (tarayıcıda dürüstçe simüle edilemez) AML.TA0010 · Sızdırma

Açıklama

Türkçe çeviri henüz mevcut değil; resmi İngilizce açıklama gösteriliyor (uydurma çeviri yapılmaz).

AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary. Sensitive information can be encoded into the tool's input parameters and transmitted to an adversary-controlled location (such as an inbox, document, or server) as part of a seemingly legitimate action. Variants include sending emails, creating or modifying documents, updating CRM records, or even generating media such as images or videos. The invoked tool itself may be legitimate but invoked by an adversary via LLM Prompt Injection, or the tool may be malicious (See AI Agent Tool Poisoning). AI Agent Tool Poisoning can also be used to manipulate the inputs and destination of a separate legitimate tool, invoked through normal usage by the victim.

Dürüstlük rozeti gerekçesi

Sızdırma çoğunlukla gerçek model/çıkarım API erişimine bağlıdır; bazı alt-teknikler kavram olarak gösterilebilir (bkz. üyelik çıkarımı), gerisi altyapı ister.

Kaynak

← Matrise dön