A CIA Triad-Based Taxonomy of Prompt Attacks on Large Language Models

Nicholas Jones, Md Whaiduzzaman, Tony Jan, Amr Adel, Ammar Alazab, Afnan Alkreisat

Research output: Contribution to journalArticlepeer-review

Abstract

The rapid proliferation of Large Language Models (LLMs) across industries such as healthcare, finance, and legal services has revolutionized modern applications. However, their increasing adoption exposes critical vulnerabilities, particularly through adversarial prompt attacks that compromise LLM security. These prompt-based attacks exploit weaknesses in LLMs to manipulate outputs, leading to breaches of confidentiality, corruption of integrity, and disruption of availability. Despite their significance, existing research lacks a comprehensive framework to systematically understand and mitigate these threats. This paper addresses this gap by introducing a taxonomy of prompt attacks based on the Confidentiality, Integrity, and Availability (CIA) triad, an important cornerstone of cybersecurity. This structured taxonomy lays the foundation for a unique framework of prompt security engineering, which is essential for identifying risks, understanding their mechanisms, and devising targeted security protocols. By bridging this critical knowledge gap, the present study provides actionable insights that can enhance the resilience of LLM to ensure their secure deployment in high-stakes and real-world environments.

Original languageEnglish
Article number113
JournalFuture Internet
Volume17
Issue number3
DOIs
Publication statusPublished - Mar 2025

Keywords

  • CIA triad
  • large language model
  • mitigation protocols
  • prompt attack
  • prompt security engineering
  • taxonomy

Fingerprint

Dive into the research topics of 'A CIA Triad-Based Taxonomy of Prompt Attacks on Large Language Models'. Together they form a unique fingerprint.

Cite this