Researchers have demonstrated an attack against xAI’s Grok large language model that uses encrypted malicious instructions to trick the assistant into disclosing user chat records and other personal information. According to the report, xAI was informed of the vulnerability in June, but Grok was still leaking data at the time the story was published. The attack is described as similar in principle to an earlier attack this week on Microsoft 365 Copilot Enterprise, with both cases exploiting prompt injection. In these scenarios, the model struggles to tell apart legitimate user instructions and hidden malicious instructions embedded in the content it is asked to process. Experts cited in the report said large language models cannot fundamentally solve this category of severe vulnerability, leaving developers to rely on guardrails that restrict harmful actions rather than eliminate the underlying problem.
Researchers have demonstrated an attack method against Grok, the large language model developed by xAI, showing that encrypted malicious instructions can trick the assistant into exposing user chat records and other personal information.
According to the report, xAI was informed about the vulnerability in June. As of the time of publication, however, the assistant was still leaking data.
Attack relies on prompt injection
The method is similar in principle to an attack reported earlier this week against Microsoft 365 Copilot Enterprise. In both cases, the issue centers on prompt injection: the model has difficulty distinguishing between direct user instructions and hidden malicious instructions embedded in the content it is asked to process.
Experts say the flaw is hard to eliminate at the model level
Experts said large language models cannot fundamentally solve this most serious class of vulnerability. Instead, developers are largely limited to putting guardrails in place to prevent models from carrying out harmful actions.
The report was attributed to Ars Technica AI and summarized by Techub.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.