UNSEEN: AR-LLM 기반 사회 공학 공격에 대한 전층 LLM 학습 제거 방어 기술
UNSEEN: A Cross-Stack LLM Unlearning Defense against AR-LLM Social Engineering Attacks
최근 등장하고 있는 AR-LLM 기반 사회 공학 공격(예: SEAR)은 현실 세계의 사회 생활에 심각한 위협을 초래할 수 있습니다. 이러한 AR-LLM 기반 사회 공학 공격에서 공격자는 AR 글래스를 활용하여 대상의 이미지 및 음성 정보를 수집하고, LLM을 사용하여 대상을 식별하고 소셜 프로필을 생성하며, LLM 에이전트를 사용하여 대화 제안을 통해 대상의 신뢰를 얻고, 이후 피싱 공격을 수행합니다. 현재의 접근 제어 또는 데이터 흐름 추적과 같은 방어 기술은 AR 기기와 불투명한 LLM 추론을 고려한 통합 AR-LLM 환경에 직접적으로 적용하기 어렵습니다. 따라서 기존의 개인 정보 보호 패러다임으로는 해결하기 어려운 새로운 수준의 사회 공학적 위협이 존재합니다. 이를 해결하기 위해서는 법률 및 사용자 교육과 같은 인간 중심적인 조치 외에도, 시행 가능한 공급업체 정책 및 플랫폼 수준의 제한이 필요합니다. 이러한 비전을 실현하기 위해서는 자원 제약적인 AR 기기의 보안, 불투명한 LLM 추론 내에서의 세분화된 접근 제어 구현, 그리고 적응형 대화형 에이전트 관리에 대한 기술적인 어려움이 존재합니다. 이러한 문제점을 해결하기 위해, 우리는 AR 접근 제어 계층(ACL)을 통한 인증 기반 센서 제어, F-RMU 기반 LLM 학습 제거를 통한 민감한 프로필 정보 보호, 그리고 런타임 에이전트 가이드레일을 통한 적응형 상호 작용 제어를 결합한 통합 방어 기술인 UNSEEN을 제안합니다. 우리는 IRB 승인을 받은 사용자 연구를 통해 60명의 참가자와 현실적인 사회 시나리오를 기반으로 한 360개의 어노테이션된 대화 데이터 세트를 사용하여 UNSEEN을 평가했습니다.
Emerging AR-LLM-based Social Engineering attack (e.g., SEAR) is at the edge of posing great threats to real-world social life. In such AR-LLM-SE attack, the attacker can leverage AR (Augmented Reality) glass to capture the image and vocal information of the target, using the LLM to identify the target and generate the social profile, using the LLM agents to apply social engineering strategies for conversation suggestion to win the target trust and perform phishing afterwards. Current defensive approaches, such as role-based access control or data flow tracking, are not directly applicable to the convergent AR-LLM ecosystem (considering embedded AR device and opaque LLM inference), leaving an emerging and potent social engineering threat that existing privacy paradigms are ill-equipped to address. This necessitates a shift beyond solely human-centric measures like legislation and user education toward enforceable vendor policies and platform-level restrictions. Realizing this vision, however, faces significant technical challenges: securing resource-constrained AR-embedded devices, implementing fine-grained access control within opaque LLM inferences, and governing adaptive interactive agents. To address these challenges, we present UNSEEN, a coordinated cross-stack defense that combines an AR ACL (Access Control Layer) for identity-gated sensing, F-RMU-based LLM unlearning for sensitive profile suppression, and runtime agent guardrails for adaptive interaction control. We evaluate UNSEEN in an IRB-approved user study with 60 participants and a dataset of 360 annotated conversations across realistic social scenarios.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.