Skip to content
Search
paper2024ReviewedOpen access

ConfusedPilot: Confused Deputy Risks in RAG-based LLMs

Ayush RoyChowdhury, Mulong Luo, Prateek Sahu, Sarbartha Banerjee, Mohit Tiwari

arXiv preprint

Abstract

Introduces confused deputy attacks against RAG-based code assistants like GitHub Copilot, where poisoned code repositories manipulate assistant outputs.

Categories

#RAG#code-assistant#confused-deputy

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM08Vector and Embedding Weaknesses
OWASP Top 10 for Agentic Applications
  • ASI01Agent Goal Hijack
  • ASI04Agentic Supply Chain Compromise

Cite

@misc{roychowdhury2024confusedpilot,
  title = {{ConfusedPilot: Confused Deputy Risks in RAG-based LLMs}},
  author = {Ayush RoyChowdhury and Mulong Luo and Prateek Sahu and Sarbartha Banerjee and Mohit Tiwari},
  year = {2024},
  eprint = {2408.04870},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2408.04870}
}