Special Token Injection (STI) Attack Guide
blog.sentry.security | 博客 | #ai-security | #pentesting | #prompt-injection | #llm | #special-token-injection | #chatml
摘要
面向渗透测试人员解读 Special Token Injection(STI):保留 token 与聊天模板转义不足时,攻击者可覆盖系统提示词、伪造消息角色并劫持 LLM 工具调用。
- 发布时间
- 收录时间
Skip to content