OpenAI introduces a memory feature in ChatGPT that allows it to recall information across sessions. However, this feature also comes with risks, as it can be manipulated by attackers to store false memories or instructions. Three attack avenues are explored: connected apps, uploaded documents, and browsing. The post provides
Table of contents
What is Memory in an LLM app?Memories in ChatGPTHacking Memory with Prompt Injection?Scenario 1: Connected AppsScenario 2: Analyzing an Image (File Uploads)Scenario 3: Browsing with BingDisclosureRecommendationsConclusionAppendixReferencesSort: