Measuring Malicious Intermediary Attacks on the LLM Supply Chain
A systematic study examining malicious intermediary attacks on LLM supply chains is presented.
Large language models (LLMs) increasingly depend on third-party API routers that act as application-layer proxies. These routers have full plaintext access to JSON payloads but lack cryptographic integrity enforcement. This study systematically examines this attack surface, formalizing a threat model for malicious LLM API routers and defining two main attack classes: payload injection and secret exfiltration. The findings reveal that several routers actively inject malicious code and can exploit benign configurations, highlighting significant security risks for LLM deployments.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work