AI-Native LLM Security by Vaibhav Malik Ken Huang Ads Dawson

AI-Native LLM Security by Vaibhav Malik Ken Huang Ads Dawson

Author:Vaibhav Malik , Ken Huang, Ads Dawson
Language: eng
Format: epub
Publisher: Packt Publishing
Published: 2025-11-28T00:00:00+00:00


Table 9.2 – Demonstrating the OWASP Top 10 vulnerabilities’ relevance to cloud-based LLM applications

Each vulnerability presents unique challenges for LLM application providers, particularly in cloud environments where ease of deployment, scalability, and integration with third-party services can inadvertently introduce risks. Understanding these vulnerabilities enables providers to implement robust security measures, ensuring that their applications remain resilient against potential threats while maximizing the benefits of cloud-based solutions.

That being said, adopting a cloud provider’s infrastructure so that it can host an LLM application can be advantageous for developers. As well as their efficiency and cost-effectiveness, there are security-related benefits to using services provided by cloud providers to build LLM applications. Let’s consider an example of hosting an integrated code interpreter where a client can interact with a chatbot with coding capabilities. This was illustrated in Chapter 8, and it was shown to be a vector for attackers to foothold, pivot, laterally move, and potentially remain persistent through this kind of feature. This application integration can map to several of the OWASP Top 10 vulnerabilities, but the most prominent is Insecure Plugin Design.

Let’s look at the benefits of using cloud-based deployments for chatbots and conversational agents:

Isolation and security by design:Serverless architecture: By leveraging serverless computing services such as AWS Lambda, Google Cloud Functions, and Azure Functions, each code execution request runs in a stateless environment that is inherently isolated from other processes. This isolation means that if an attacker attempts to exploit vulnerabilities within the embedded code interpreter, their access is limited to that specific execution context, significantly reducing the potential blast radius of any attack.

Example: If malicious code is executed through the embedded interpreter, it cannot affect the underlying infrastructure or other running applications, as each function execution is contained within its own secure environment.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Popular ebooks
Eco-friendly approach of bio-indigo synthesis and developing purification methods towards isolation of indigo from indirubin and bacterial fragments by Ramalingam Manivannan & Kaliyan Prabakaran & Young-A Son(165614)
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(157790)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74282)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(66084)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(65834)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(65272)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50860)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40226)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40194)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40058)
What's Done in Darkness by Kayla Perrin(27111)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26485)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26436)
The Ultimate Python Exercise Book: 700 Practical Exercises for Beginners with Quiz Questions by Copy(21023)
De Souza H. Master the Age of Artificial Intelligences. The Basic Guide...2024 by Unknown(20781)
D:\Jan\FTP\HOL\Work\Alien Breed - Tower Assault CD32 Alien Breed II - The Horror Continues Manual 1.jpg by PDFCreator(20651)
The Fifty Shades Trilogy & Grey by E L James(19608)
Shot Through the Heart: DI Grace Fisher 2 by Isabelle Grey(19488)
Shot Through the Heart by Mercy Celeste(19351)
Python GUI Applications using PyQt5 : The hands-on guide to build apps with Python by Verdugo Leire(17495)