Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
MAI-2024-0037
Published:August 01, 2024
Updated:August 02, 2026
The Cross-Prompt Injection Attack (XPIA) can be significantly intensified by incorporating a Greedy Coordinate Gradient (GCG) suffix into the malicious payload. This technique enhances the probability that a Large Language Model (LLM) will execute the embedded instruction, even when a user's primary directive is present, thereby facilitating data exfiltration. The effectiveness of this attack is contingent upon the complexity of the LLM, with models of medium complexity demonstrating heightened susceptibility. Mitigation steps: **For AI Developers:** * Implement advanced prompt filtering techniques to identify and mitigate malicious injections, with a focus on detecting GCG suffixes. * Sanitize and validate function calls generated by the LLM prior to execution to prevent misuse of external access tools. **For Model Trainers/Fine-tuners:** * Utilize more complex LLMs, as they demonstrate increased resistance to specific attack vectors. * Develop specialized methods for detecting and neutralizing GCG suffixes within the model. * Apply varied defense strategies tailored to the complexity of LLMs, acknowledging that the effectiveness of defenses like prompt filtering can vary significantly.
Related Resources (1)
Do you need more information?
Contact Us
CVSS v4
Base Score:
8.2
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.9
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
AIVSS
Base Score:
5.9