2024ReviewedOpen access
ConfusedPilot: Confused Deputy Risks in RAG-based LLMs
Ayush RoyChowdhury, Mulong Luo, Prateek Sahu, Sarbartha Banerjee, Mohit Tiwari
arXiv preprint
Abstract
Introduces confused deputy attacks against RAG-based code assistants like GitHub Copilot, where poisoned code repositories manipulate assistant outputs.
Categories
#RAG#code-assistant#confused-deputy
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM08Vector and Embedding Weaknesses
OWASP Top 10 for Agentic Applications
- ASI01Agent Goal Hijack
- ASI04Agentic Supply Chain Compromise
Cite
@misc{roychowdhury2024confusedpilot,
title = {{ConfusedPilot: Confused Deputy Risks in RAG-based LLMs}},
author = {Ayush RoyChowdhury and Mulong Luo and Prateek Sahu and Sarbartha Banerjee and Mohit Tiwari},
year = {2024},
eprint = {2408.04870},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2408.04870}
}