MSIT Releases Manual on 21 LLM Threats
Key point
The Ministry of Science and ICT (MSIT) and the Korea Internet & Security Agency (KISA) have released a diagnostic and response manual covering 21 security threats to LLM systems.
Details
The Ministry of Science and ICT (MSIT) and the Korea Internet & Security Agency (KISA) have released a 231-page Korean manual that classifies 21 security threats to LLM systems and outlines diagnostic methods and response measures for each threat.
Authored by the KISA AI Security Red Team, this document underwent consultation with a practical working group and academic review. It targets entire LLM systems—combining retrieval, data, external tools, and agents—rather than standalone models.
Key contents include:
- Jailbreaking and prompt injection
- Indirect prompt injection
- Agent tool misuse
- Model and data supply chain compromise
- Three-tier classification and diagnostic procedures for LLM system threats
- Industry-specific security scenarios and response design
This manual serves as a follow-up to the existing "Artificial Intelligence (AI) Security Guide." While red team execution procedures are covered in a separate "AI Security Red Teaming Guide," this document focuses on threat classification, diagnostics, and response frameworks. It identifies security teams, CISOs and CSOs, SOC analysts, and vulnerability assessment personnel, as well as AI developers and system operators, as key audiences.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.