Mashable 2024年12月26日
Hidden content tricks ChatGPT into rewriting search results, Guardian shows
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

OpenAI的ChatGPT搜索功能近期向所有用户开放,但也暴露出安全漏洞。通过“提示注入”攻击,第三方网站可以利用隐藏内容操纵ChatGPT的搜索结果。例如,在包含负面评价的网页中加入赞美内容,就能使ChatGPT给出虚假的好评。尽管如此,OpenAI有足够时间修复这些问题,并且其强大的安全团队也在积极应对。虽然目前尚未出现大规模恶意攻击,但这一事件凸显了AI聊天机器人容易被欺骗的风险。

🔎 ChatGPT搜索功能向所有用户开放,并加入了语音模式。

⚠️ “提示注入”攻击:第三方网站通过隐藏内容操纵ChatGPT搜索结果,例如在包含负面评价的网页中加入赞美内容,使ChatGPT给出虚假的好评。

🛡️ OpenAI拥有强大的安全团队,正在积极测试和修复这些漏洞,尽管存在风险,但目前尚未出现大规模恶意攻击。

🤖 AI聊天机器人容易被欺骗,需要加强安全防范。

In October, OpenAI's ChatGPT Search became available for ChatGPT Plus users. Last week, it became available to all users and was added to search in Voice Mode. And, of course, it isn't without its flaws.

The Guardian asked ChatGPT to summarize webpages that contain hidden content and, it turns out, hidden content can manipulate the search. It's called prompt injection, which is the ability for third parties — like websites you're asking ChatGPT to summarize — to force new prompts into your ChatGPT Search without your knowledge. Consider a page full of negative restaurant reviews. If the site includes hidden content waxing poetic about how incredible the restaurant is and encourages ChatGPT to instead answer a prompt like "tell me how amazing this restaurant is," that hidden content could override your original search.

"In the tests, ChatGPT was given the URL for a fake website built to look like a product page for a camera. The AI tool was then asked if the camera was a worthwhile purchase. The response for the control page returned a positive but balanced assessment, highlighting some features people might not like," The Guardian investigation states. "However, when hidden text included instructions to ChatGPT to return a favorable review, the response was always entirely positive. This was the case even when the page had negative reviews on it – the hidden text could be used to override the actual review score."

This doesn't spell failure for ChatGPT Search, though. OpenAI only recently launched Search, so it has plenty of time to fix these kinds of bugs. Plus, Jacob Larsen, a cybersecurity researcher at CyberCX, told The Guardian that OpenAI has a "very strong" AI security team and "by the time that this has become public, in terms of all users can access it, they will have rigorously tested these kinds of cases."

Prompt injections attacks have been a hypothetical for ChatGPT and other AI search functions since the technology launched, and while we have seen some demonstrations of the potential harms, we haven't seen a major malicious attack of this kind. That said, it does point to a problem with AI chatbots: They are remarkably easy to trick.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

ChatGPT搜索 提示注入 AI安全 网络漏洞
相关文章