TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated Applications
Junjie He, Shenao Wang, Yanjie Zhao, Xinyi Hou, Zhao Liu, Quanchen Zou, Haoyu Wang
摘要
Large Language Models (LLMs) have revolutionized numerous domains, enabling the development of LLM-integrated applications that autonomously plan and act through tool calling. While these applications demonstrate remarkable capabilities, their ability to invoke sensitive operations, such as file system interactions, code execution, and database queries, introduces critical security risks. In particular, prompt injection vulnerabilities, combined with security-sensitive sink functions, can lead to a broad class of attacks we define as Prompt-to-Anything Injection (P2Xi). These vulnerabilities, stemming from the misuse of LLM-generated outputs without proper validation, can result in severe consequences such as Remote Command Execution (RCE), file injection, SQL injection, and Server-Side Request Forgery (SSRF). To address this emerging threat, we propose TaintP2X, a novel static taint analysis framework that models LLM-generated outputs as taint sources, tracks their propagation through sensitive sink functions, and employs LLM-assisted analysis to prune false positives. TaintP2X achieves high precision and scalability, systematically identifying P2Xi vulnerabilities. In evaluations, TaintP2X demonstrated a 77.1% recall on a ground truth dataset of 35 P2Xi vulnerabilities, outperforming state-of-the-art methods. With TaintP2X, we have uncovered 101 taint paths across 75 open source repositories, with 7 vulnerabilities confirmed by developers, and 5 of them fixed. These findings highlight the prevalence and impact of P2Xi vulnerabilities and establish TaintP2X as a practical solution for securing LLM-integrated ecosystems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Toolformer: Language Models Can Teach Themselves to Use ToolsTimo Schick, Jane Dwivedi-Yu, Roberto Dessì, Roberta Raileanu 等NeurIPS 2023 · 被引用 5,989 次
- ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIsYujia Qin, Shihao Liang, Yining Ye, Kunlun Zhu 等ICLR 2024 · 被引用 1,469 次
- Using an LLM to Help With Code UnderstandingDaye Nam, Andrew Macvean, Vincent J. Hellendoorn, Bogdan Vasilescu 等ICSE 2024 · 被引用 264 次
- Mobile-Agent-v2: Mobile Device Operation Assistant with Effective Navigation via Multi-Agent CollaborationJunyang Wang, Haiyang Xu, Haitao Jia, Xi Zhang 等NeurIPS 2024 · 被引用 245 次
- Demystifying LLM-Based Software Engineering AgentsChunqiu Steven Xia, Yinlin Deng, Soren Dunn, Lingming ZhangFSE 2025 · 被引用 36 次
相关 Paper
- Prompt-to-SQL Injections in LLM-Integrated Web Applications: Risks and DefensesRodrigo Pedro, Miguel E. Coimbra, Daniel Castro, Paulo Carreira 等ICSE 2025 · 被引用 14 次
- Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based AgentsFengyu Liu, Yuan Zhang, Jiaqi Luo, Jiarun Dai 等USENIX Security 2025
- Demystifying RCE Vulnerabilities in LLM-Integrated AppsTong Liu, Zizhuang Deng, Guozhu Meng, Yuekang Li 等CCS 2024 · 被引用 19 次
- Disentangling Adversarial Prompts: A Semantic-Graph Defense for Robust LLM SecurityXiang Fang, Wanlong FangAAAI 2026 · 被引用 4 次
- Reframing Paths as Logic: Semantic Segmentation for Vulnerability DetectionZong Cao, Yuqiang Sun, Zhengzi Xu, Kaixuan Li 等OOPSLA 2026
