Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
102 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
43 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Opening A Pandora's Box: Things You Should Know in the Era of Custom GPTs (2401.00905v1)

Published 31 Dec 2023 in cs.CR

Abstract: The emergence of LLMs has significantly accelerated the development of a wide range of applications across various fields. There is a growing trend in the construction of specialized platforms based on LLMs, such as the newly introduced custom GPTs by OpenAI. While custom GPTs provide various functionalities like web browsing and code execution, they also introduce significant security threats. In this paper, we conduct a comprehensive analysis of the security and privacy issues arising from the custom GPT platform. Our systematic examination categorizes potential attack scenarios into three threat models based on the role of the malicious actor, and identifies critical data exchange channels in custom GPTs. Utilizing the STRIDE threat modeling framework, we identify 26 potential attack vectors, with 19 being partially or fully validated in real-world settings. Our findings emphasize the urgent need for robust security and privacy measures in the custom GPT ecosystem, especially in light of the forthcoming launch of the official GPT store by OpenAI.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (6)
  1. Guanhong Tao (33 papers)
  2. Siyuan Cheng (41 papers)
  3. Zhuo Zhang (42 papers)
  4. Junmin Zhu (3 papers)
  5. Guangyu Shen (21 papers)
  6. Xiangyu Zhang (328 papers)
Citations (9)

Summary

We haven't generated a summary for this paper yet.