CERT-In Advisory - Security Implications of AI Language-Based Applications, 9 May 2023
AI / PRIVACY / CYBER RELEVANCE
Useful operational guidance for LLM use, especially against sharing credentials, financial information or other sensitive data.
AI: Very HighPrivacy: HighCybersecurity: Very High
READ FIRST
- Security implications and recommended controls for AI language applications
- monitoring, MFA and incident response
PURVIEW
Addresses the specific security implications of AI language-based applications, including risks arising from prompt manipulation, unsafe outputs, information exposure, misuse and the broader attack surface created when language models are connected to applications and data. For privacy, the advisory is especially relevant where prompts, documents, conversations or connected data sources contain personal or confidential information. It therefore helps security teams and AI developers identify concrete threat scenarios and integrate secure-design, access-control, monitoring and data-protection measures into LLM deployments.
Classification and legal status. Advisory / non-binding technical guidance.