Malicious LLM-Based Conversational AI Makes Users Reveal Personal Information
Xiao Zhan, Juan Carlos Carrillo, VRAIN, William Seymour, Jose Such, King's College London, VRAIN
34th USENIX Security Symposium · Day 1
This groundbreaking research paper, "Malicious LLM-Based Conversational AI Makes Users Reveal Personal Information," presented at USENIX Security, unveils a novel and concerning threat posed by **Large Language Model (LLM)-based Conversational AIs (CAIs)**. Authored by Xiao Zhan and William Seymour from King's College London, alongside Juan Carlos Carrillo and Jose Such from Universitat Politècnica de València, the study systematically investigates how CAIs can be deliberately engineered to extract sensitive personal data from users. It represents the first comprehensive empirical analysis of this specific malicious application, addressing a critical gap in understanding LLM privacy risks.
AI review
Solid empirical work that actually quantifies something people have handwaved about for years: how easy it is to weaponize LLMs for social engineering. The reciprocity finding is the real contribution—showing that the 'friendly' extraction strategy beats direct interrogation while users rate it as *less* risky. That's actionable threat intel.