Description
Dans cette vidéo, on dissèque les trois familles d'attaques contre les LLM et les agents : manipuler le modèle, lui faire fuiter des secrets, et détourner une IA qui peut agir. Plus comment on se défend.
Aucun prérequis technique lourd. Cadre 100 % défensif et pédagogique.
📚 Pour aller plus loin :
— OWASP Top 10 for LLM Applications : https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
— Blog de Simon Willison sur la prompt injection : https://simonwillison.net/
🔔 Abonne-toi à Projets IA — on démonte l'IA en profondeur, un concept par vidéo.
#PromptInjection #SécuritéIA #IA #Cybersécurité #LLM #IntelligenceArtificielle #OWASP #Jailbreak #AgentIA #MachineLearning #VulgarisationIA #ProjetsIA
---
# 🔗 SOURCES (vérifiées)
- **Prompt injection (nom + première démonstration)** — Riley Goodside démontre l'attaque (sept. 2022) ; Simon Willison nomme la « prompt injection » par analogie à l'injection SQL. Réf : simonwillison.net (série « prompt injection »).
- **Injection indirecte** — Greshake, Abdelnabi, Mishra, Endres, Holz, Fritz : « Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection », arXiv:2302.12173 (fév. 2023). Exploits démontrés notamment contre Bing Chat (GPT-4).
- **Suffixe adversarial / jailbreak automatisé (GCG)** — Zou, Wang, Carlini, Nasr, Kolter, Fredrikson : « Universal and Transferable Adversarial Attacks on Aligned Language Models » (2023). Suffixes universels et transférables entre modèles.
- **Régurgitation de données d'entraînement** — littérature sur la mémorisation/extraction de données d'entraînement des LLM (p. ex. Carlini et al., « Extracting Training Data from Large Language Models »).
- **Classement des risques + défenses** — **OWASP Top 10 for LLM Applications** (LLM01 Prompt Injection = risque n°1, non « patchable » ; LLM02 Sensitive Information Disclosure ; défense en profondeur : moindre privilège, human-in-the-loop, filtrage entrée/sortie) - https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
---
# 🏷️ HASHTAGS
```
#PromptInjection #SécuritéIA #IA #Cybersécurité #LLM #IntelligenceArtificielle #OWASP #Jailbreak #AgentIA #MachineLearning #VulgarisationIA #ProjetsIA
Hosted on Ausha. See ausha.co/privacy-policy for more information.





