Attack Type

Data Extraction

Data extraction attacks target the information processed or memorised by AI/ML systems. They take three main forms. First, training-data extraction: large language models can memorise verbatim spans of their training corpus, and an attacker who crafts the right prompts can pull back PII, API keys, or copyrighted text — a result demonstrated against GPT-2 by Carlini et al. and reproduced against several production models. Second, model extraction: by repeatedly querying a hosted model and observing outputs, an attacker can reconstruct enough behaviour to clone proprietary fine-tunes. Third, system-prompt and conversation leakage: indirect prompt injection or insecure logging can leak the application's instructions and other users' conversations. Multi-tenant inference platforms (vLLM, Triton, hosted APIs) and RAG systems are particularly exposed. Defenses: output filtering, differential privacy in training, rate limits, and strict tenant isolation.

952
Total CVEs
48
Pages
Page 48 of 48
Current
Severity CVE CVSS
CRITICAL CVE-2026-72811 10.0
MEDIUM CVE-2026-73560 6.5
CRITICAL CVE-2026-64849 9.3
HIGH CVE-2026-35219 -
MEDIUM CVE-2026-8810 6.9
HIGH CVE-2026-76254 7.5
HIGH CVE-2026-77071 -
HIGH CVE-2026-72848 8.6
HIGH CVE-2026-55540 7.1
HIGH CVE-2026-55526 8.5
HIGH CVE-2026-55525 7.5
HIGH CVE-2026-45019 7.2

Page 48 of 48