Sunday, June 1, 2025
  • Home
  • About Us
  • Disclaimer
  • Contact Us
  • Terms & Conditions
  • Privacy Policy
T3llam
  • Home
  • App
  • Mobile
    • IOS
  • Gaming
  • Computing
  • Tech
  • Services & Software
  • Home entertainment
No Result
View All Result
  • Home
  • App
  • Mobile
    • IOS
  • Gaming
  • Computing
  • Tech
  • Services & Software
  • Home entertainment
No Result
View All Result
T3llam
No Result
View All Result
Home Tech

Hacker crops false recollections in ChatGPT to steal consumer knowledge in perpetuity

admin by admin
September 24, 2024
in Tech
0
Hacker crops false recollections in ChatGPT to steal consumer knowledge in perpetuity
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Hacker plants false memories in ChatGPT to steal user data in perpetuity

Getty Photographs

When safety researcher Johann Rehberger lately reported a vulnerability in ChatGPT that allowed attackers to retailer false data and malicious directions in a consumer’s long-term reminiscence settings, OpenAI summarily closed the inquiry, labeling the flaw a security challenge, not, technically talking, a safety concern.

So Rehberger did what all good researchers do: He created a proof-of-concept exploit that used the vulnerability to exfiltrate all consumer enter in perpetuity. OpenAI engineers took discover and issued a partial repair earlier this month.

Strolling down reminiscence lane

The vulnerability abused long-term dialog reminiscence, a characteristic OpenAI started testing in February and made extra broadly out there in September. Reminiscence with ChatGPT shops data from earlier conversations and makes use of it as context in all future conversations. That method, the LLM can pay attention to particulars equivalent to a consumer’s age, gender, philosophical beliefs, and just about anything, so these particulars don’t should be inputted throughout every dialog.

Inside three months of the rollout, Rehberger discovered that recollections could possibly be created and completely saved by means of oblique immediate injection, an AI exploit that causes an LLM to comply with directions from untrusted content material equivalent to emails, weblog posts, or paperwork. The researcher demonstrated how he might trick ChatGPT into believing a focused consumer was 102 years previous, lived within the Matrix, and insisted Earth was flat and the LLM would incorporate that data to steer all future conversations. These false recollections could possibly be planted by storing recordsdata in Google Drive or Microsoft OneDrive, importing photographs, or searching a web site like Bing—all of which could possibly be created by a malicious attacker.

Rehberger privately reported the discovering to OpenAI in Could. That very same month, the corporate closed the report ticket. A month later, the researcher submitted a brand new disclosure assertion. This time, he included a PoC that brought on the ChatGPT app for macOS to ship a verbatim copy of all consumer enter and ChatGPT output to a server of his selection. All a goal wanted to do was instruct the LLM to view an internet hyperlink that hosted a malicious picture. From then on, all enter and output to and from ChatGPT was despatched to the attacker’s web site.

ChatGPT: Hacking Recollections with Immediate Injection – POC

“What is absolutely attention-grabbing is that is memory-persistent now,” Rehberger mentioned within the above video demo. “The immediate injection inserted a reminiscence into ChatGPT’s long-term storage. Whenever you begin a brand new dialog, it truly remains to be exfiltrating the info.”

The assault isn’t attainable by means of the ChatGPT net interface, due to an API OpenAI rolled out final 12 months.

Whereas OpenAI has launched a repair that forestalls recollections from being abused as an exfiltration vector, the researcher mentioned, untrusted content material can nonetheless carry out immediate injections that trigger the reminiscence instrument to retailer long-term data planted by a malicious attacker.

LLM customers who wish to forestall this type of assault ought to pay shut consideration throughout classes for output that signifies a brand new reminiscence has been added. They need to additionally frequently evaluate saved recollections for something which will have been planted by untrusted sources. OpenAI offers steering right here for managing the reminiscence instrument and particular recollections saved in it. Firm representatives didn’t reply to an e mail asking about its efforts to forestall different hacks that plant false recollections.

RelatedPosts

Ransomware kingpin “Stern” apparently IDed by German legislation enforcement

Ransomware kingpin “Stern” apparently IDed by German legislation enforcement

May 31, 2025
Fueling seamless AI at scale

Fueling seamless AI at scale

May 31, 2025
Elon Musk is lobbying lawmakers on driverless automobile guidelines

Elon Musk is lobbying lawmakers on driverless automobile guidelines

May 31, 2025


Hacker plants false memories in ChatGPT to steal user data in perpetuity

Getty Photographs

When safety researcher Johann Rehberger lately reported a vulnerability in ChatGPT that allowed attackers to retailer false data and malicious directions in a consumer’s long-term reminiscence settings, OpenAI summarily closed the inquiry, labeling the flaw a security challenge, not, technically talking, a safety concern.

So Rehberger did what all good researchers do: He created a proof-of-concept exploit that used the vulnerability to exfiltrate all consumer enter in perpetuity. OpenAI engineers took discover and issued a partial repair earlier this month.

Strolling down reminiscence lane

The vulnerability abused long-term dialog reminiscence, a characteristic OpenAI started testing in February and made extra broadly out there in September. Reminiscence with ChatGPT shops data from earlier conversations and makes use of it as context in all future conversations. That method, the LLM can pay attention to particulars equivalent to a consumer’s age, gender, philosophical beliefs, and just about anything, so these particulars don’t should be inputted throughout every dialog.

Inside three months of the rollout, Rehberger discovered that recollections could possibly be created and completely saved by means of oblique immediate injection, an AI exploit that causes an LLM to comply with directions from untrusted content material equivalent to emails, weblog posts, or paperwork. The researcher demonstrated how he might trick ChatGPT into believing a focused consumer was 102 years previous, lived within the Matrix, and insisted Earth was flat and the LLM would incorporate that data to steer all future conversations. These false recollections could possibly be planted by storing recordsdata in Google Drive or Microsoft OneDrive, importing photographs, or searching a web site like Bing—all of which could possibly be created by a malicious attacker.

Rehberger privately reported the discovering to OpenAI in Could. That very same month, the corporate closed the report ticket. A month later, the researcher submitted a brand new disclosure assertion. This time, he included a PoC that brought on the ChatGPT app for macOS to ship a verbatim copy of all consumer enter and ChatGPT output to a server of his selection. All a goal wanted to do was instruct the LLM to view an internet hyperlink that hosted a malicious picture. From then on, all enter and output to and from ChatGPT was despatched to the attacker’s web site.

ChatGPT: Hacking Recollections with Immediate Injection – POC

“What is absolutely attention-grabbing is that is memory-persistent now,” Rehberger mentioned within the above video demo. “The immediate injection inserted a reminiscence into ChatGPT’s long-term storage. Whenever you begin a brand new dialog, it truly remains to be exfiltrating the info.”

The assault isn’t attainable by means of the ChatGPT net interface, due to an API OpenAI rolled out final 12 months.

Whereas OpenAI has launched a repair that forestalls recollections from being abused as an exfiltration vector, the researcher mentioned, untrusted content material can nonetheless carry out immediate injections that trigger the reminiscence instrument to retailer long-term data planted by a malicious attacker.

LLM customers who wish to forestall this type of assault ought to pay shut consideration throughout classes for output that signifies a brand new reminiscence has been added. They need to additionally frequently evaluate saved recollections for something which will have been planted by untrusted sources. OpenAI offers steering right here for managing the reminiscence instrument and particular recollections saved in it. Firm representatives didn’t reply to an e mail asking about its efforts to forestall different hacks that plant false recollections.

Previous Post

Mediatek units the date for Dimensity 9400 announcement

Next Post

What Was Introduced Throughout Sony’s State of Play Livestream for September 2024?

Next Post
What Was Introduced Throughout Sony’s State of Play Livestream for September 2024?

What Was Introduced Throughout Sony's State of Play Livestream for September 2024?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • App (3,061)
  • Computing (4,367)
  • Gaming (9,536)
  • Home entertainment (633)
  • IOS (9,461)
  • Mobile (11,797)
  • Services & Software (3,965)
  • Tech (5,279)
  • Uncategorized (4)

Recent Posts

  • Repairability is lastly going mainstream. Kind of.
  • The battle to play Borderlands On-line continues, as devoted archivists ask for assist in pursuit of the lengthy misplaced MMO
  • Ransomware kingpin “Stern” apparently IDed by German legislation enforcement
  • NYT Strands hints and solutions for Sunday, June 1 (recreation #455)
  • Consumer Information for Odoo POS Supply Display screen
  • App
  • Computing
  • Gaming
  • Home entertainment
  • IOS
  • Mobile
  • Services & Software
  • Tech
  • Uncategorized
  • Home
  • About Us
  • Disclaimer
  • Contact Us
  • Terms & Conditions
  • Privacy Policy

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • App
  • Mobile
    • IOS
  • Gaming
  • Computing
  • Tech
  • Services & Software
  • Home entertainment

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies. However you may visit Cookie Settings to provide a controlled consent.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analyticsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functionalThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessaryThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-othersThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performanceThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policyThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Save & Accept