S0123RS3-T10-S0123-Z · Full risk code

Covert Goal Hijacking

目標劫持隱蔽執行

Verification & Validation
Risk Description

When the system appears to complete the user's request normally while embedding additional content in its output per injected instructions; due to unmitigated control gaps, because the primary task result is correct, the anomaly goes undetected for a long period, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM01、LLM05
MITRE ATLASAML.T0051
NIST AI 600-1Information Security
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Verify output-goal consistency, comparing content against the scope of the user's original request; Separate instructions from data architecturally so instructions in external content cannot alter task goals; Scan and intercept anomalous embeddings—links or extra directives—in outputs