AltaySec · ATLAS 2026.07
AML.T0092

Manipulate User LLM Chat History

Bu tekniğin yerleşik Türkçe adı henüz terminoloji kanonuna eklenmedi; İngilizce adı gösteriliyor.

C · Açıklama (tarayıcıda dürüstçe simüle edilemez) AML.TA0007 · Savunmadan Kaçınma

Açıklama

Türkçe çeviri henüz mevcut değil; resmi İngilizce açıklama gösteriliyor (uydurma çeviri yapılmaz).

Adversaries may manipulate a user's large language model (LLM) chat history to cover the tracks of their malicious behavior. They may hide persistent changes they have made to the LLM's behavior, or obscure their attempts at discovering private information about the user. To do so, adversaries may delete or edit existing messages or create new threads as part of their coverup. This is feasible if the adversary has the victim's authentication tokens for the backend LLM service or if they have direct access to the victim's chat interface. Chat interfaces (especially desktop interfaces) often do not show the injected prompt for any ongoing chat, as they update chat history only once when initially opening it. This can help the adversary's manipulations go unnoticed by the victim.

Dürüstlük rozeti gerekçesi

Bu teknik gerçek bir savunma yığınına karşı ölçülmelidir; tarayıcıda en fazla basit bir filtre-karşı-filtre gösterimi dürüst olur.

Kaynak

← Matrise dön