Shifting from Injection to Interaction: Rethinking Web Security in the Age of LLMs and Beyond
Nivedita Singh, Alsharif Abuadbba, Yansong Gao, Surya Nepal, Hyoungshick Kim
Abstract
Large language models (LLMs) are becoming integral to web applications and browser agents, transforming online interactions while introducing new attack vectors and reshaping longstanding web vulnerabilities. Classical threats such as cross-site scripting (XSS) can be amplified through LLM-mediated interactions, while LLM-specific vulnerabilities can propagate across web applications, introducing attacks such as prompt injection. Securing modern web systems therefore requires understanding interactions between traditional and LLM-specific threats across the system lifecycle. Unlike prior surveys treating web and LLM security separately, this survey provides a unified analysis of how LLMs amplify web vulnerabilities across client-side, server-side, and pipeline layers while evaluating defenses and their limitations. The analysis examines extending NIST and ISO/IEC AI security frameworks to the security needs of LLM-enabled web environments. Three unresolved challenges are identified: adversarial natural-language instructions, autonomous agent security, and post-deployment security through continuous monitoring and adaptation. An LLM-aware monitoring and control framework is proposed, integrating semantic input validation, prompt integrity protection, output isolation, agent governance, and runtime monitoring. This unified perspective characterizes the evolving threat landscape and outlines future directions for secure AI-enabled web systems.
Create a lesson
Related papers
Decreasing Digital Distraction in College Students: Associated Online Learning Strategies Identified by Unsupervised Data Mining Approaches
Hui Shi, Ran Bi, Xi Lin et al.
Making Gender-Inclusive Practices Actionable: Evaluating a Research-Informed Computing Education Toolkit
Alina Berry, Susan McKeever, Brenda Murphy et al.
Bridging Formal and Perceived Fairness: Development of an Interdisciplinary Framework in Algorithmic Decision-Making
Maike Lindermayr, Mattia Cerrato, Luisa Hübner et al.
Open WebXR versus Commercial Game Engines: A Socio-Technical Position Analysis for an Open, Sustainable, and Interoperable Metaverse
Luca Turchet, Michel Buffa
The 5P Reflection Model for Education in the Generative Artificial Intelligence (GenAI) Era
Rajan Kadel, Samar Shailendra, Islam Mohammad Tahidul et al.
Multilingual Agent System for Inclusive Wildfire Evacuation Guidance
Shruti Kulkarni, Lynn Tong, Aditi Namboodiripad et al.