Cybersecurity Risks of Application-Integrated General-Purpose AI Models
Why embedding large language models into applications - with tool use, data access, and execution - reintroduces classical cybersecurity vulnerabilities. Students learn how prompt injection and indirect prompt injection let user- or attacker-supplied text override intended instructions because current models cannot reliably separate instructions from data, and how the field responds through benchmarking, auditing, dynamic auto red-teaming, and foundational guarantees such as differential privacy and robustness certification rather than empirical testing alone.
Fundamental Risks in the Current Deployment of General-Purpose AI Models: What Have We (Not) Learnt
Extended abstract (European AI Office workshop) arguing that the deployment of general-purpose AI - large language models embedded in applications with tool use, data access and execution - reintrodu…