公開LLM基盤への攻撃をハニーポットで観測
OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure
この論文をやさしく読む
ひとことで言うと
Ollama APIに見せかけた観測用サーバーを設置し、公開LLMサービスに届く攻撃の種類と量を測った研究。
何に役立つ?
公開LLM基盤の監視や防御で、実際に観測された探査と悪用の種類を優先順位付けする参考になる。
この研究の面白いところ
84日間、4配置、約29万件のやり取りを集め、基盤への攻撃とプロンプト層への攻撃の両方を記録している。
どこまで分かった?
観測は4つの配置と84日間に限られる。ハニーポットへの試みを示しており、実サービスで攻撃が成功した割合は要旨に示されていない。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
公開状態の大規模言語モデル(LLM)基盤は攻撃対象領域を広げているが、実際の標的化の様子は十分に分かっていない。著者らは、背後にLLMを置かずにOllama APIを模倣する低・中対話型ハニーポットOllureを提示する。クラウドと大学ネットワークにまたがる4つの配置で84日間運用し、2,793の異なる送信元IPアドレスから290,887件のやり取りを記録した。活動の大半は自動的な発見、特徴識別、モデルの列挙だった。一方、基盤とLLM層の双方に対する具体的な悪用の試みも観測した。これにはモデル管理機能の悪用、パストラバーサルとSSRFの探査、遠隔コード実行と暗号資産マイニングのペイロード、資源枯渇の試み、プロンプトインジェクション、情報抽出、エージェントを意識したツール使用が含まれる。結果は、公開された自己ホスト型LLMサービスが現実に直面する脅威について、実測に基づく知見を提供する。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-24(UTC)
- 最新改訂
- 2026-09-24 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-24 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, Ollure operated for 84 days and recorded 290,887 interactions from 2,793 unique source IP addresses. Most of the activity consisted of automated discovery, fingerprinting, and model enumeration. However, we also observed concrete exploitation attempts against both the infrastructure and LLM layers. These included model management abuse, path traversal and SSRF probes, RCE and cryptocurrency mining payloads, resource exhaustion attempts, prompt injection, information extraction, and agent-oriented tool use. Our results provide empirical insight into real-world threats against exposed, self-hosted LLM services.
著者のコメント
24 pages, 7 figures
arXiv ID: 2609.29757 / 要約の誤りについて