← Back to feed
AI SecurityEmerging1 sourceSep 16, 2023 · 07:00via Embrace The Red (AI agent security)

LLM Apps: Don't Get Stuck in an Infinite Loop! 💵💰

Brief

What happens if an attacker calls an LLM tool or plugin recursively during an Indirect Prompt Injection? Could this be an issue and drive up costs, or DoS a system?

I tried it with ChatGPT, and it indeed works and the Chatbot enters a loop! 😊

However, for ChatGPT users this isn’t really a threat, because:

  • It’s subscription based, so OpenAI would pay the bill.
  • There seems to be a call limit of 10 times in a single conversation turn (I tried a few times).
  • Lastly, one can click “Stop Generating” if the loop keeps ongoing.

BUT

Read more on Embrace The Red (AI agent security)