Hacker vegetation false reminiscences in ChatGPT to steal consumer knowledge in perpetuity

Hacker plants false memories in ChatGPT to steal user data in perpetuity

Getty Photos

When safety researcher Johann Rehberger just lately reported a vulnerability in ChatGPT that allowed attackers to retailer false info and malicious directions in a consumer’s long-term reminiscence settings, OpenAI summarily closed the inquiry, labeling the flaw a security challenge, not, technically talking, a safety concern.

So Rehberger did what all good researchers do: He created a proof-of-concept exploit that used the vulnerability to exfiltrate all consumer enter in perpetuity. OpenAI engineers took discover and issued a partial repair earlier this month.

Strolling down reminiscence lane

The vulnerability abused long-term dialog reminiscence, a function OpenAI started testing in February and made extra broadly out there in September. Reminiscence with ChatGPT shops info from earlier conversations and makes use of it as context in all future conversations. That means, the LLM can pay attention to particulars reminiscent of a consumer’s age, gender, philosophical beliefs, and just about anything, so these particulars don’t must be inputted throughout every dialog.

Inside three months of the rollout, Rehberger discovered that reminiscences might be created and completely saved by way of oblique immediate injection, an AI exploit that causes an LLM to comply with directions from untrusted content material reminiscent of emails, weblog posts, or paperwork. The researcher demonstrated how he might trick ChatGPT into believing a focused consumer was 102 years outdated, lived within the Matrix, and insisted Earth was flat and the LLM would incorporate that info to steer all future conversations. These false reminiscences might be planted by storing recordsdata in Google Drive or Microsoft OneDrive, importing photos, or shopping a web site like Bing—all of which might be created by a malicious attacker.

Rehberger privately reported the discovering to OpenAI in Might. That very same month, the corporate closed the report ticket. A month later, the researcher submitted a brand new disclosure assertion. This time, he included a PoC that brought on the ChatGPT app for macOS to ship a verbatim copy of all consumer enter and ChatGPT output to a server of his alternative. All a goal wanted to do was instruct the LLM to view an internet hyperlink that hosted a malicious picture. From then on, all enter and output to and from ChatGPT was despatched to the attacker’s web site.

ChatGPT: Hacking Reminiscences with Immediate Injection – POC

“What is basically fascinating is that is memory-persistent now,” Rehberger mentioned within the above video demo. “The immediate injection inserted a reminiscence into ChatGPT’s long-term storage. While you begin a brand new dialog, it really remains to be exfiltrating the info.”

The assault isn’t doable by way of the ChatGPT internet interface, because of an API OpenAI rolled out final yr.

Whereas OpenAI has launched a repair that stops reminiscences from being abused as an exfiltration vector, the researcher mentioned, untrusted content material can nonetheless carry out immediate injections that trigger the reminiscence software to retailer long-term info planted by a malicious attacker.

LLM customers who need to stop this type of assault ought to pay shut consideration throughout periods for output that signifies a brand new reminiscence has been added. They need to additionally commonly evaluation saved reminiscences for something which will have been planted by untrusted sources. OpenAI supplies steering right here for managing the reminiscence software and particular reminiscences saved in it. Firm representatives didn’t reply to an e mail asking about its efforts to stop different hacks that plant false reminiscences.

Leave a Reply

Your email address will not be published. Required fields are marked *