arrow
返回

Securing large language models: A quantitative assurance framework approach

delete2026-01-21
delete0
delete
OA
AI
S
Sander Stamnes Karlsen
M
Muhammad Mudassar Yamin
E
Ehtesham Hashmi *
B
Basel Katt
M
Mohib Ullah
DOI:10.1016/j.jisa.2025.104351delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Large Language Models (LLMs) are increasingly integrated into sensitive domains such as healthcare and autonomous systems, yet adoption is constrained by security risks that conventional assurance methods do not capture. Traditional software assurance techniques are inadequate for LLM-specific vulnerabilities, including prompt injection, insecure output handling, and training data poisoning. We introduce a quantitative security assurance framework for LLM applications that translates security requirements and vulnerabilities into measurable scores. The framework computes an Assurance Metric (AM) as AM = RM - VM, where VM is weighted using CVSS v4.0, and maps results to five security assurance levels, making security posture comparable, auditable, and actionable. Requirements span input/output validation, training data, development and deployment, access control, third-party services, and security procedures; vulnerability tests align with the OWASP Top 10 for LLMs (prompt injection, insecure output handling, training data poisoning, denial of service, sensitive information disclosure, overreliance, and model theft). Case study results show uncensored models (e.g., Llama2-uncensored) exhibit significantly higher exposure, especially to prompt injection and output-handling attacks-while censored and fine-tuned models attain higher assurance levels. Significance and impact: the framework provides transparent, quantitative scoring to compare systems, prioritize mitigations, and support evidence-based deployment and governance in high-takes environments, with continuous human oversight emphasized.
Keyword:
Large language models
Security assurance framework
Quantitative security assessment
LLM vulnerabilities
Security architecture
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

暂无机构信息
引用论文

引用论文

err分享
err收藏
(Security) Assertions by Large Language Models(安全性) 大型语言模型的断言
err2024-01-01
err10
errOAAI
errKande, Rahul; Pearce, Hammond; Tan, Benjamin; Dolan-Gavitt, Brendan; Thakur, Shailja; Karri, Ramesh; Rajendran, Jeyavijayan
err分享
err收藏
TAJ
err2009-06-15
err0
PREAI
errOmer Tripp; Marco Pistoia; Stephen J. Fink; Manu Sridharan; Omri Weisman
err分享
err收藏
Automated Malware Source Code Generation via Uncensored LLMs and Adversarial Evasion of Censored Model
err
err0
PREAI
errAcosta-Bermejo,Raúl; Terrazas-Chavez,José Alexis; Aguirre-Anaya,Eleazar
err分享
err收藏
PromptRobust: Towards Evaluating the Robustness of Large Language Models on Adversarial Prompts
err2024-11-19
err0
PREAI
errKaijie Zhu; Jindong Wang; Jiaheng Zhou; Zichen Wang; Hao Chen; Yidong Wang; Linyi Yang; Wei Ye; Yue Zhang; Neil Gong; Xing Xie
err分享
err收藏
没有更多内容