Aller au contenu principal
Accès ouvert déclaré 2025 conference-paper

Prompt-to-SQL Injections in LLM-Integrated Web Applications: Risks and Defenses

21Citations signalées, ce qui n’est pas une note de qualité
2Institutions déclarées
1Pays d’affiliation déclarés

Rattachement africain : pt. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

Large Language Models (LLMs) have found widespread applications in various domains, including web applications with chatbot interfaces. Aided by an LLM-integration middleware such as LangChain, user prompts are translated into SQL queries used by the LLM to provide meaningful responses to users. However, unsanitized user prompts can lead to SQL injection attacks, potentially compromising the security of the database. In this paper, we present a comprehensive examination of prompt-to-SQL ($\mathbf{P}_{2} \mathbf{S Q L}$) injections targeting web applications based on frameworks such as LangChain and LlamaIndex. We characterize$\mathrm{P}_{2} \text{SQL}$injections, exploring their variants and impact on application security through multiple concrete examples. We evaluate seven state-of-the-art LLMs, demonstrating the risks of$P_{2}$SQL attacks across language models. By employing both manual and automated methods, we discovered$\mathrm{P}_{2} \text{SQL}$vulnerabilities in five real-world applications. Our findings indicate that LLMintegrated applications are highly susceptible to$\mathrm{P}_{2} \text{SQL}$injection attacks, warranting the adoption of robust defenses. To counter these attacks, we propose four effective defense techniques that can be integrated as extensions to the LangChain framework.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
Prompt-to-SQL Injections in LLM-Integrated Web Applications: Risks and Defenses
Date Crossref
01/04/2025
Éditeur
IEEE
Type
proceedings-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Les institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Web Application Security VulnerabilitiesSecurity and Verification in ComputingAdvanced Data Storage Technologies

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.