vix.ing · top · new · best · stats · spec

Is Embedding-as-a-Service Safe? Meta-Prompt-Based Backdoor Attacks for User-Specific Trigger Migration

2025/01/09 by Gaurav Bagwe, Lan Zhang, Linke Guo +3 · 1 voice
Computer Science · #Caching and Content Delivery #Network Security and Intrusion Detection #Spam and Phishing Detection

paper · pdf · doi:10.53941/tai.2025.100002

openalex publication_date 2025/01/09 · openalex created_date 2025/10/10 · openalex updated_date 2026/06/11

Abstract

Article Is Embedding-as-a-Service Safe? Meta-Prompt-Based Backdoor Attacks for User-Specific Trigger Migration Gaurav Bagwe 1,*, Lan Zhang 1, Linke Guo 1, Miao Pan 2, Xiaolong Ma 1 and Xiaoyong Yuan 1 1 Department of Electrical and Computer Engineering, Clemson University, Clemson, SC 29634, USA 2 Department of Electrical and Computer Engineering, University of Houston, Houston, TX 77204, USA * Correspondence: [email protected] Received: 20 September 2024; Revised: 18 November 2024; Accepted: 20 December 2024; Published: 9 January 2025 Abstract: Embedding-as-a-Service (EaaS) has emerged as a popular paradigm for empowering users with limited resources to leverage large language models (LLMs). Through an API, EaaS providers grant access to their large language embedding models (LLEMs), enabling users with domain expertise to construct the domain-specific layers locally. However, the close interaction between EaaS providers and users raises new concerns: Is EaaS safe for users? Although recent research has highlighted the vulnerability of LLMs to backdoor attacks, especially task-agnostic backdoor attacks, existing attacks cannot be effectively executed in EaaS due to challenges in terms of attack efficacy, attack stealthiness, and user-side knowledge limitations. To unveil backdoor threats specific to EaaS, this paper proposes a novel backdoor attack named BadEmd, designed to effectively compromise multiple EaaS users while preserving the functionality of EaaS. BadEmd comprises two key modules: meta-prompt-based attack buildup creates backdoor attack surfaces in EaaS while seamlessly integrating with prior task-agnostic attacks to ensure attack stealthiness; user-specific trigger migration enforces attack efficacy despite limited user-side knowledge. Extensive experiments demonstrate the success of BadEmd across various user tasks.

Citations

Discussions

Related