LLMLeak turns an LLM's web-fetch tool into a covert channel, reaching a 79.7% attack success rate across eleven open-parameter models
Synopsis
The paper introduces LLMLeak, a novel attack vector in which malicious software that runs locally but cannot reach the internet directly encodes a secret into a URL and presents the referenced site as information needed for a benign task such as migrating a software library, inducing the LLM to fetch that URL through its web-fetch tool so the attacker receives the encoded secret via an attacker-controlled DNS or web server; evaluation on eleven open-parameter models shows a 79.7% attack success rate, with a case study on real-world chatbots.
Figure 1 : Overview of LLMLeak ’s steps.
arXivInterpretation
The paper demonstrates a previously undescribed covert channel in which local malicious software uses an LLM's web-fetch tool to exfiltrate confidential data to a third party. Prior work focused on prompt injections and disclosure of sensitive data to chatbot providers, with countermeasures such as input structuring and local LLM deployment; this work shifts attention to leakage to third parties and notes that the channel does not rely on generated code sending data directly. Demonstrated through a concrete attack implementation, LLMLeak, evaluated on eleven open-parameter models with a reported 79.7% attack success rate, plus a case study on real-world chatbots.
The attack works because it relies only on the LLM's tool for fetching websites, which is normally treated as a legitimate feature rather than an outbound channel. The paper notes that inputs instructing the LLM to send data directly via generated code are easy to detect and that network libraries are typically restricted; LLMLeak avoids both by embedding the secret in a URL and framing the target site as information required for a benign task such as migrating a software library. The abstract supports this with both mechanism and evaluation: a client-side malicious component embeds the secret, and when the LLM accesses the URL the attacker receives the encoded secret through an attacker-controlled DNS or web server.
The risk is relevant in real-world chatbot settings, not only in laboratory conditions. Beyond the open-parameter model evaluation, the paper adds a case study on real-world chatbots to show LLMLeak's practical relevance. The case study serves as supplementary evidence alongside the reported evaluation; the abstract does not give its specific count, configuration, or outcome details.
Perspective
This work targets settings where users employ LLMs or LLM-based agents whose models have a web-fetch tool, especially client environments where a local malicious software component exists and cannot itself reach the internet directly. Its directly usable results are an attack path that encodes a secret into a URL and induces the model to fetch it under the guise of a benign task, a 79.7% attack success rate across eleven open-parameter models, and a case study on real-world chatbots. For defenders, it suggests treating model access to external URLs as a potential outbound channel; for researchers, it provides a reproducible attack setup for testing whether existing countermeasures such as input structuring and local deployment cover this path.
The abstract does not specify the exact list of eleven open-parameter models, the evaluation tasks, or the criteria used, nor the number and configuration of chatbots in the case study, so the conditions behind the 79.7% figure still need confirmation in the original paper. The abstract also does not report a defense evaluation for this channel, leaving open whether existing countermeasures such as input structuring and local LLM deployment can block LLMLeak. Because only abstract-level text is available here, without figures or experimental details, these judgments are limited to what the abstract states.
