새로운 데이터 주입 공격으로 AI 에이전트가 잘못된 명령을 실행할 위험이 있다.
최근에 발견된 데이터 주입 공격은 AI 에이전트가 신뢰하는 정보를 왜곡해 우선순위를 바꿀 수 있는 가능성을 보여준다. 예를 들어, 제품 페이지의 리뷰를 요약할 때, 악의적인 리뷰가 '구매하기' 버튼을 클릭하도록 유도할 수 있다. 또한, 코딩 어시스턴트가 GitHub의 수정 사항을 적용하려 할 때, 가짜 코멘트가 다른 사람의 명령을 실행토록 할 수 있다.
A new data injection attack can lead AI agents to misclick or execute attacker’s commands.
A recently discovered data injection attack highlights the potential for AI agents to distort the facts they rely on and change their priorities. For instance, when summarizing reviews on a product page, a malicious review could manipulate the agent to click 'Buy Now.' Similarly, when a coding assistant applies a maintainer's fix from GitHub, a fake comment could trick it into executing commands from an unknown source.