
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>HANS</title>
      <link>https://www.hansking.cn/blog</link>
      <description>A posts created with Next.js and Tailwind.css</description>
      <language>en-us</language>
      <managingEditor>admin@hansking.cn (HANS)</managingEditor>
      <webMaster>admin@hansking.cn (HANS)</webMaster>
      <lastBuildDate>Sun, 13 Oct 2024 10:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.hansking.cn/tags/Prompt Injection/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.hansking.cn/blog/2026/LLM-an-quan-PromptInjection-yu-yue-quan-gong-ju-diao-yong</guid>
    <title>LLM 安全：Prompt Injection 与越权工具调用</title>
    <link>https://www.hansking.cn/blog/2026/LLM-an-quan-PromptInjection-yu-yue-quan-gong-ju-diao-yong</link>
    <description>[{&quot;value&quot;:&quot;LLM 安全：Prompt Injection 与越权工具调用&quot;,&quot;url&quot;:&quot;#llm-安全prompt-injection-与越权工具调用&quot;,&quot;depth&quot;:1},{&quot;value&quot;:&quot;一、直接注入和间接注入&quot;,&quot;url&quot;:&quot;#一直接注入和间接注入&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;二、为什么模型很难天然区分指令和数据&quot;,&quot;url&quot;:&quot;#二为什么模型很难天然区分指令和数据&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;三、先画清数据流和信任边界&quot;,&quot;url&quot;:&quot;#三先画清数据流和信任边界&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;四、最小权限是最有效的防线&quot;,&quot;url&quot;:&quot;#四最小权限是最有效的防线&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;五、工具调用要有二次确认&quot;,&quot;url&quot;:&quot;#五工具调用要有二次确认&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;六、RAG 的安全重点是检索前后两道门&quot;,&quot;url&quot;:&quot;#六rag-的安全重点是检索前后两道门&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;七、浏览器和代码执行是高风险组合&quot;,&quot;url&quot;:&quot;#七浏览器和代码执行是高风险组合&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;八、输出过滤挡不住已经发生的副作用&quot;,&quot;url&quot;:&quot;#八输出过滤挡不住已经发生的副作用&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;九、检测注入要看行为，不只看文本&quot;,&quot;url&quot;:&quot;#九检测注入要看行为不只看文本&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;十、用攻击样本做持续测试&quot;,&quot;url&quot;:&quot;#十用攻击样本做持续测试&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;十一、日志和凭证管理决定事故能否收敛&quot;,&quot;url&quot;:&quot;#十一日志和凭证管理决定事故能否收敛&quot;,&quot;depth&quot;:2},{&quot;value&quot;:&quot;十二、我的总结：不要试图把模型变成防火墙&quot;,&quot;url&quot;:&quot;#十二我的总结不要试图把模型变成防火墙&quot;,&quot;depth&quot;:2}]</description>
    <pubDate>Sun, 13 Oct 2024 10:00:00 GMT</pubDate>
    <author>admin@hansking.cn (HANS)</author>
    <category>AI</category><category>LLM</category><category>安全</category><category>Prompt Injection</category><category>Agent</category>
  </item>

    </channel>
  </rss>
