Limboy
Brave (@brave)

AI agents that can browse the Web and perform tasks on your behalf have incredible potential but also introduce new security risks. We recently found, and disclosed, a concerning flaw in Perplexity's Comet browser that put users' accounts and other sensitive info in danger.

原来可以通过将 Prompt 隐藏在网页中(比如透明颜色或注释),来欺骗 AI 做出一些窃取隐私的事情。

文中举了一个例子,reddit 的一个帖子将 prompt 攻击信息设置为 hidden,当用户让 AI Agent summarize 页面时,就会读取到这个信息,并按照指示去做,比如获取 perplexity 的 登录信息,并发送到指定 URL。