Security · Flashcard
What is slopsquatting?
Why this is the answer
Models hallucinate plausible-sounding package names that do not exist; because the same non-existent name recurs across prompts, an attacker can register it and wait for developers to install the suggestion. Resembling a real name is classic typosquatting, impersonating a lab is model-hub squatting, and pushing unreviewed generated code is a contribution-review problem.
Read more in the docsMore AI and LLM Application Security flashcards
- What distinguishes an indirect prompt injection from a direct one?
- Where does the real risk lie when an application's system prompt leaks?
- What does a training-data poisoning attack do?
- What does an AI-BOM inventory beyond a conventional software bill of materials?
- On what basis does the EU AI Act impose obligations?
