SecureFlow 案例索引
以下每個案例都是有來源依據的 AI 攻擊流程,並逐步對應到 AIDEFEND 的防禦技術。點進案例可以看摘要與威脅技術對照,也可以直接開啟互動式流程圖。
已發布 123 條攻擊流程
AIDEFEND 研究流程
- aidefend-sf0000從提示詞注入攻擊到 agent 工具濫用
- aidefend-sf0001以 Sentry MCP 遙測注入挾持程式開發 agent(Agentjacking)
- aidefend-sf0002SearchLeak:透過 Microsoft 365 Copilot 一鍵外洩資料
- aidefend-sf0003Cowork Exfil:透過 Microsoft 365 Copilot Cowork 的被投毒 skill 外洩檔案
- aidefend-sf0004Prompt-to-Shell:Microsoft Semantic Kernel 中的兩條遠端程式碼執行路徑
- aidefend-sf0005Copirate 365:在 Microsoft 365 Copilot 中以記憶體後門長期外洩資料(CVE-2026-24299)
- aidefend-sf0006自備 agent:把暴露在外的 LLM 後端當成攻擊者的 AI 運算資源
- aidefend-sf0007LiteLLM 護欄測試端點的沙箱逃逸與 root 權限遠端程式碼執行
- aidefend-sf0008以巢狀 api_base 從 LiteLLM 連線測試外洩金鑰
- aidefend-sf0009JADEPUFFER:利用 Langflow 遠端程式碼執行漏洞的 agentic 勒索攻擊
- aidefend-sf0010DifyTap:Dify 的跨租戶 AI 資料暴露
- aidefend-sf0011Amazon Q 自動載入 MCP 設定,一路走到雲端憑證遭竊
- aidefend-sf0012PerplexedBrowser:Comet 被挾持去攻擊 1Password
- aidefend-sf0013看似乾淨的儲存庫,如何讓 AI 程式開發 agent 從 DNS 取回並執行反向 shell
- aidefend-sf0014AutoJack:從網頁內容打進本機 agent 控制面的遠端程式碼執行
- aidefend-sf0015ChainLeak:Chainlit 任意檔案讀取與 SSRF,一路通到雲端
- aidefend-sf0016LangGraph checkpointer 的 SQL 注入與反序列化遠端程式碼執行
- aidefend-sf0017PerplexedBrowser:Comet 把本機檔案外洩出去
- aidefend-sf0018Salesforce Einstein 的提示詞地雷攻擊,造成 CRM 資料被竄改
- aidefend-sf0019AgentFlayer:ChatGPT Connectors 的零點擊資料外洩
- aidefend-sf0020Moltbook agent 網路的回呼分布圖
- aidefend-sf0021OpenAI Atlas 網址列的提示詞注入攻擊
- aidefend-sf0022NVIDIA Triton Python 後端的免驗證遠端程式碼執行攻擊鏈
- aidefend-sf0023Ollama for Windows 自動更新造成的長期遠端程式碼執行
- aidefend-sf0024Notion AI agent 的間接提示詞注入與資料外洩
- aidefend-sf0025AgentForger:偽造 ChatGPT Workspace Agent,讓惡意 agent 在企業內部自主執行
- aidefend-sf0026OpenAI 評估 Agent 入侵 Hugging Face 正式環境
- aidefend-sf0027Stolen Thoughts:從不透明推理區塊還原機敏內容
- aidefend-sf0028Flowise CSV Agent 提示詞注入繞過檢查並執行 Python
- aidefend-sf0029MLflow Webhook 轉址讓伺服器讀取內部資源
- aidefend-sf0030惡意網頁連到 Ray Jobs API 並執行指令
- aidefend-sf0031Miasma 利用儲存庫設定啟動憑證竊取程式
- aidefend-sf0032仿冒 Agent Skill:先累積人氣,再換成惡意內容竊取憑證
- aidefend-sf0033Copilot for Word 隱藏提示詞文件蠕蟲
- aidefend-sf0034DuneSlide:Cursor 兩條沙箱逃逸路徑導向未隔離 RCE
- aidefend-sf0035Computer-Use TOCTOU:Agent 看到的畫面不是最後點到的畫面
- aidefend-sf0036Rogue Agent:一個 Dialogflow 權限就能入侵整個專案的共用執行環境
- aidefend-sf0037RovoBlast:點一次 rovoChatPrompt 連結就能外洩資料
- aidefend-sf0038Atlassian Rovo 文件提示詞注入與 URL 外洩
- aidefend-sf0039CoSnitch:Copilot Web 自動執行資料外洩
- aidefend-sf0040CoSnitch:Copilot Web 長期記憶投毒
- aidefend-sf0041Spyder:Sider 跨來源合成事件攻擊
- aidefend-sf0042MaXSS:MaxAI 通用背景 API 橋接造成 UXSS
- aidefend-sf0043CVE-2026-66384 Artifactory 容器映像快取下毒
- aidefend-sf0044Artifactory RubyGem 反序列化漏洞:從竊取簽章金鑰到偽造管理員 JWT
- aidefend-sf0045OpenAI 研究環境遭入侵:一條利用 Linux 核心漏洞,另一條偽造管理員 JWT
- aidefend-sf0046加密內容注入(Cryptographic Context Injection):網頁加密指令繞過靜態檢查,誘導 AI 執行環境外洩資料
- aidefend-sf0047GitSpawn:程式碼代理程式尚未取得信任,專案庫就能先執行惡意命令
- aidefend-sf0048一封藏有偽造對話的電子郵件,串起多條瀏覽器帳號攻擊路徑(Claude-Site Scripting)
- aidefend-sf0049SkillJack:遭投毒的代理程式經驗,被提煉成暗藏後門的持久技能
MITRE ATLAS 案例研究
- mitre-atlas-cs0000規避惡意程式 C&C 流量的深度學習偵測器
- mitre-atlas-cs0001規避殭屍網路的網域生成演算法(DGA)偵測
- mitre-atlas-cs0002VirusTotal 遭投毒
- mitre-atlas-cs0003繞過 Cylance 的 AI 惡意程式偵測
- mitre-atlas-cs0004以劫持相機的方式攻擊人臉辨識系統
- mitre-atlas-cs0005針對機器翻譯服務的攻擊
- mitre-atlas-cs0006Clearview AI 設定錯誤導致私有原始碼庫外洩
- mitre-atlas-cs0007複製 GPT-2 模型
- mitre-atlas-cs0008ProofPoint 郵件防護遭規避
- mitre-atlas-cs0009Tay 遭資料投毒
- mitre-atlas-cs0010Microsoft Azure 服務中斷演練
- mitre-atlas-cs0011規避 Microsoft 邊緣 AI 模型
- mitre-atlas-cs0012以實體對抗物規避人臉辨識系統
- mitre-atlas-cs0013針對行動 App 中深度學習模型的後門攻擊
- mitre-atlas-cs0014混淆防毒神經網路的判定
- mitre-atlas-cs0015PyTorch 相依套件鏈遭汙染
- mitre-atlas-cs0016以提示詞注入在 MathGPT 上達成程式碼執行
- mitre-atlas-cs0017繞過 ID.me 的身分驗證
- mitre-atlas-cs0018在 Google Colab 上執行任意程式碼
- mitre-atlas-cs0019PoisonGPT:把植入假事實的模型混進 Hugging Face
- mitre-atlas-cs0020間接提示詞注入攻擊:Bing Chat 被改造成套取個資的海盜
- mitre-atlas-cs0021ChatGPT 對話內容遭外洩
- mitre-atlas-cs0022ChatGPT 幻覺出不存在的套件名稱
- mitre-atlas-cs0023ShadowRay:挾持暴露在外的 Ray 叢集
- mitre-atlas-cs0024Morris II 蠕蟲:以 RAG 為途徑的攻擊
- mitre-atlas-cs0025網路規模資料集投毒:分歧視角攻擊
- mitre-atlas-cs0026把 M365 Copilot 當成內鬼,挾持金融匯款作業
- mitre-atlas-cs0027Hugging Face 上的組織身分混淆
- mitre-atlas-cs0028以供應鏈攻擊竄改 AI 模型
- mitre-atlas-cs0029Google Bard 對話內容遭外洩
- mitre-atlas-cs0030LLM Jacking:盜用雲端 LLM 資源
- mitre-atlas-cs0031Hugging Face 上的惡意模型
- mitre-atlas-cs0032試圖規避 ML 釣魚網頁偵測系統
- mitre-atlas-cs0033以即時深偽影像注入規避行動裝置的 KYC 驗證
- mitre-atlas-cs0034ProKYC:用於帳號詐騙的深偽工具
- mitre-atlas-cs0035以間接提示詞注入從 Slack AI 外洩資料
- mitre-atlas-cs0036AIKatz:攻擊 LLM 桌面應用程式
- mitre-atlas-cs0037透過 Copilot Studio 中的 agent 工具外洩資料
- mitre-atlas-cs0038植入指令,讓 AI agent 延後自動呼叫工具
- mitre-atlas-cs0039Living Off AI:透過 Jira Service Management 的提示詞注入攻擊
- mitre-atlas-cs0040以提示詞注入竄改 ChatGPT 的記憶
- mitre-atlas-cs0041Rules File Backdoor:針對 AI 程式開發助理的供應鏈攻擊
- mitre-atlas-cs0042SesameOp:新型後門程式把 OpenAI Assistants API 當成命令與控制通道
- mitre-atlas-cs0043惡意程式原型內嵌提示詞注入攻擊
- mitre-atlas-cs0044LAMEHUG:用 AI 即時產生命令的惡意程式
- mitre-atlas-cs0045透過 Cursor 使用的 MCP server 外洩資料
- mitre-atlas-cs0046以間接提示詞注入攻擊 Claude Computer Use,造成資料被刪除
- mitre-atlas-cs0047Amazon Q VS Code 擴充套件中被發現可部署破壞性 AI agent 的程式碼
- mitre-atlas-cs0048暴露在外的 ClawdBot 控制介面,導致憑證外洩與命令執行
- mitre-atlas-cs0049以被投毒的 ClawdBot Skill 發動供應鏈攻擊
- mitre-atlas-cs0050OpenClaw 的一鍵遠端程式碼執行
- mitre-atlas-cs0051OpenClaw 透過提示詞注入建立命令與控制通道
- mitre-atlas-cs0052LLMSmith:整合 LLM 的應用程式中的遠端程式碼執行漏洞
- mitre-atlas-cs0053被投毒的 Postmark MCP server 外洩郵件內容
- mitre-atlas-cs0054透過遠端被投毒的 MCP 工具外洩資料
- mitre-atlas-cs0055AI ClickFix:用 ClickFix 手法挾持 computer-use agent
- mitre-atlas-cs0056針對 Anthropic Claude 的模型蒸餾行動
- mitre-atlas-cs0057Storm-2139 繞過 Azure OpenAI 的安全防護機制
- mitre-atlas-cs0058Google 相簿 AI 模型遭萃取
- mitre-atlas-cs0059EchoLeak:針對 M365 Copilot 的零點擊提示詞注入資料外洩
- mitre-atlas-cs0060以提示詞操弄在聯想 AI 聊天機器人上造成跨網站腳本攻擊
- mitre-atlas-cs0061AI in the Middle:把網頁版 AI 服務當成 C2 中繼站
- mitre-atlas-cs0062Semantic Kernel 搜尋外掛的遠端程式碼執行漏洞
- mitre-atlas-cs0063透過日曆邀請對 Gemini 發動提示詞攻擊
- mitre-atlas-cs0064遭投毒的 GGUF 範本:推論階段供應鏈攻擊
- mitre-atlas-cs0065模型命名空間重複使用供應鏈攻擊
- mitre-atlas-cs0066ZombieAgent:對 ChatGPT 的資料外洩攻擊
- mitre-atlas-cs0067Claude Code GitHub Action 機敏憑證外洩
- mitre-atlas-cs0068OpenAI 評測 agent 逃出沙箱、入侵 Hugging Face 正式環境
- mitre-atlas-cs0069GTG-1002 用被越獄的 Claude Code agent 自主執行網路間諜行動
- mitre-atlas-cs0070DeepSeek 驅動 Hermes Agent 嘗試入侵 Langflow 與 n8n:已記錄的嘗試未得手
- mitre-atlas-cs0071多 agent 框架入侵台灣政府系統
- mitre-atlas-cs0072AI 推薦投毒:摘要連結夾帶指令,企圖改寫 AI 助理的長期記憶