A Survey on Large Language Model (LLM) Security and Privacy: The Good, the Bad, and the Ugly
Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, Yue, Zhang

TL;DR
This survey reviews how large language models enhance security and privacy while also presenting vulnerabilities and threats, highlighting the need for further research in safe deployment and attack mitigation.
Contribution
It categorizes existing literature into benefits, threats, and vulnerabilities of LLMs in security, providing a comprehensive overview and identifying research gaps.
Findings
LLMs improve code security and data privacy over traditional methods.
They can be exploited for attacks due to human-like reasoning abilities.
Research on model extraction attacks is limited and mostly theoretical.
Abstract
Large Language Models (LLMs), such as ChatGPT and Bard, have revolutionized natural language understanding and generation. They possess deep language comprehension, human-like text generation capabilities, contextual awareness, and robust problem-solving skills, making them invaluable in various domains (e.g., search engines, customer support, translation). In the meantime, LLMs have also gained traction in the security community, revealing security vulnerabilities and showcasing their potential in security-related tasks. This paper explores the intersection of LLMs with security and privacy. Specifically, we investigate how LLMs positively impact security and privacy, potential risks and threats associated with their use, and inherent vulnerabilities within LLMs. Through a comprehensive literature review, the paper categorizes the papers into "The Good" (beneficial LLM applications),…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Artificial Intelligence in Healthcare and Education · Topic Modeling
MethodsIs Venmo Customer Support Available 24/7? How to Reach a Real Person · Multi-Head Attention · 15 Ways to Contact How can i speak to someone at Delta Airlines · Attention Is All You Need · Linear Layer · Cosine Annealing · Attention Dropout · Dropout · Dense Connections · Byte Pair Encoding
