When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs
Hanna Kim, Minkyoo Song, Seung Ho Na, Seungwon Shin, Kimin Lee

TL;DR
This paper investigates the malicious potential of web-enabled Large Language Models (LLMs) in cyberattacks, demonstrating their high effectiveness in data theft, impersonation, and spear-phishing, and highlighting the urgent need for security safeguards.
Contribution
It provides a comprehensive analysis of how web-enabled LLM agents can be exploited for cyberattacks, revealing their high success rates and exposing security vulnerabilities.
Findings
LLM agents achieved up to 95.9% precision in collecting PII
93.9% of impersonation posts were deemed authentic
Phishing click rates increased by 46.67% with LLM assistance
Abstract
Recent advancements in Large Language Models (LLMs) have established them as agentic systems capable of planning and interacting with various tools. These LLM agents are often paired with web-based tools, enabling access to diverse sources and real-time information. Although these advancements offer significant benefits across various applications, they also increase the risk of malicious use, particularly in cyberattacks involving personal information. In this work, we investigate the risks associated with misuse of LLM agents in cyberattacks involving personal data. Specifically, we aim to understand: 1) how potent LLM agents can be when directed to conduct cyberattacks, 2) how cyberattacks are enhanced by web-based tools, and 3) how affordable and easy it becomes to launch cyberattacks using LLM agents. We examine three attack scenarios: the collection of Personally Identifiable…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs· youtube
Taxonomy
TopicsLegal Education and Practice Innovations · Business Law and Ethics · Law, AI, and Intellectual Property
