#attack-vectors
-
Insecure Output Handling: LLM05:2025 Attacks and Defenses
Insecure output handling turns model text into XSS, SQL injection, or remote code execution. The attack chain, the CVEs it produced, and the controls.
-
Direct vs. Indirect Prompt Injection: Threats and Defenses
Direct and indirect prompt injection are fundamentally different attacks with different attack surfaces, threat actors, mitigations, and blast radius.
-
Model Extraction vs. Model Inversion: Two Confidentiality Attacks
Model extraction and model inversion both threaten model confidentiality, but they target different assets and call for entirely different defenses.