RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    어텐션 패턴 분석을 활용한 다층 프롬프트 인젝션 탐지 프레임워크 = Multi-Level Prompt Injection Detection Framework Using Attention Pattern Analysis

    한글로보기

    https://www.riss.kr/link?id=A110290677

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
      • URL 복사
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    대규모 언어 모델(LLM)의 활용이 확대됨에 따라 사용자 입력을 악용하여 모델의 보안 정책을 우회하는 프롬프트 인젝션 공격이 급증하고 있다.
    이를 방지하기 위해 제안된 기존의 방어 기법들은 규칙 기반 탐지로 인해 정확도가 낮거나, 모델 기반 탐지로 높은 연산 비용 문제가 발생하여실시간 서비스 환경에 적용하기 어렵다. 이에 본 연구는 금지어 기반 필터링과 어텐션 패턴 분석(Attention Tracker)를 결합한 고효율 다층 방어탐지 프레임워크를 제안한다. 제안하는 시스템은 1단계에서 공격 키워드를 필터링하여 시스템 부하를 최소화하고, 2단계에서 Focus Score를 통해LLM의 어텐션 가중치 변화를 분석함으로써 문맥 조작 공격을 식별한다. 실제 악성 프롬프트 데이터셋을 이용한 실험 결과, 제안 기법은 기존단일 모델 대비 지연 시간을 50% 이상 단축하였으며, 동시에 약 2배 향상된 탐지 정확도(83%)를 달성하였다. 이를 통해 연산 효율성과 탐지 성능을동시에 확보함으로써, LLM 서비스 환경에서 안정적으로 운용 가능한 실용적인 보안 탐지 체계를 제시하였다.
    번역하기

    대규모 언어 모델(LLM)의 활용이 확대됨에 따라 사용자 입력을 악용하여 모델의 보안 정책을 우회하는 프롬프트 인젝션 공격이 급증하고 있다. 이를 방지하기 위해 제안된 기존의 방어 기법...

    대규모 언어 모델(LLM)의 활용이 확대됨에 따라 사용자 입력을 악용하여 모델의 보안 정책을 우회하는 프롬프트 인젝션 공격이 급증하고 있다.
    이를 방지하기 위해 제안된 기존의 방어 기법들은 규칙 기반 탐지로 인해 정확도가 낮거나, 모델 기반 탐지로 높은 연산 비용 문제가 발생하여실시간 서비스 환경에 적용하기 어렵다. 이에 본 연구는 금지어 기반 필터링과 어텐션 패턴 분석(Attention Tracker)를 결합한 고효율 다층 방어탐지 프레임워크를 제안한다. 제안하는 시스템은 1단계에서 공격 키워드를 필터링하여 시스템 부하를 최소화하고, 2단계에서 Focus Score를 통해LLM의 어텐션 가중치 변화를 분석함으로써 문맥 조작 공격을 식별한다. 실제 악성 프롬프트 데이터셋을 이용한 실험 결과, 제안 기법은 기존단일 모델 대비 지연 시간을 50% 이상 단축하였으며, 동시에 약 2배 향상된 탐지 정확도(83%)를 달성하였다. 이를 통해 연산 효율성과 탐지 성능을동시에 확보함으로써, LLM 서비스 환경에서 안정적으로 운용 가능한 실용적인 보안 탐지 체계를 제시하였다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As the utilization of Large Language Models (LLMs) expands, prompt injection attacks, which manipulate user inputs to bypass modelsecurity policies, have emerged as a significant threat. Existing defense techniques have faced limitations in actual service environmentsdue to the trade-off between the low accuracy of rule-based methods and the high computational costs of model-based detection. Toaddress these challenges, this study proposes a high-efficiency multi-level de4fense framework that combines Banned Terms Filteringwith Attention Pattern Analysis (Attention Tracker). The proposed system minimizes system load by filtering explicit attack keywords inthe first stage and identifies sophisticated attacks that manipulate context by analyzing changes in the LLM’s attention weights usingthe Focus Score in the second stage. Experimental results using a dataset of actual malicious prompts demonstrate that the proposedmethod reduces latency by over 50% and lowers computational costs compared to existing single-model approaches, while achievingapproximately a two-fold increase in detection accuracy (83%). This study is significant in that it presents a practical security detectionsy stem capable of stable operation in LLM service environments by effectively securing both computational efficiency and detectionperformance.
    번역하기

    As the utilization of Large Language Models (LLMs) expands, prompt injection attacks, which manipulate user inputs to bypass modelsecurity policies, have emerged as a significant threat. Existing defense techniques have faced limitations in actual ser...

    As the utilization of Large Language Models (LLMs) expands, prompt injection attacks, which manipulate user inputs to bypass modelsecurity policies, have emerged as a significant threat. Existing defense techniques have faced limitations in actual service environmentsdue to the trade-off between the low accuracy of rule-based methods and the high computational costs of model-based detection. Toaddress these challenges, this study proposes a high-efficiency multi-level de4fense framework that combines Banned Terms Filteringwith Attention Pattern Analysis (Attention Tracker). The proposed system minimizes system load by filtering explicit attack keywords inthe first stage and identifies sophisticated attacks that manipulate context by analyzing changes in the LLM’s attention weights usingthe Focus Score in the second stage. Experimental results using a dataset of actual malicious prompts demonstrate that the proposedmethod reduces latency by over 50% and lowers computational costs compared to existing single-model approaches, while achievingapproximately a two-fold increase in detection accuracy (83%). This study is significant in that it presents a practical security detectionsy stem capable of stable operation in LLM service environments by effectively securing both computational efficiency and detectionperformance.

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼