AAISM · Question #86
An organization has implemented a natural language processing model to respond to customer questions when personnel are not available. A pre-implementation security assessment revealed attackers…
The correct answer is C. Implementing input validation and templates. Chat interface injection attacks (such as prompt injection) exploit the model by crafting malicious inputs that manipulate the AI into revealing sensitive data or taking unintended actions. Input validation ensures user-supplied text conforms to expected, safe formats, while…
Question
An organization has implemented a natural language processing model to respond to customer questions when personnel are not available. A pre-implementation security assessment revealed attackers could access sensitive company data through a chat interface injection attack. Which of the following is the BEST way to prevent this attack?
Options
- AEnsuring continuous monitoring and data tagging
- BManually reviewing AI model outputs
- CImplementing input validation and templates
- DConducting regular information security audits
How the community answered
(26 responses)- A19% (5)
- B8% (2)
- C69% (18)
- D4% (1)
Explanation
Chat interface injection attacks (such as prompt injection) exploit the model by crafting malicious inputs that manipulate the AI into revealing sensitive data or taking unintended actions. Input validation ensures user-supplied text conforms to expected, safe formats, while response templates constrain what the model can return - together they block malicious payloads at the entry and exit points. Option A (continuous monitoring and data tagging) is a detective control, not a preventive one. Option B (manual review of outputs) is reactive and impractical at scale. Option D (security audits) identifies vulnerabilities but does not directly block injection attacks.
Topics
Community Discussion
No community discussion yet for this question.