Proceedings of the 22nd ACM Internet Measurement Conference 2022
DOI: 10.1145/3517745.3561433
|View full text |Cite
|
Sign up to set email alerts
|

Exploring the security and privacy risks of chatbots in messaging services

Abstract: The unprecedented adoption of messaging platforms for work and recreation has made it an attractive target for malicious actors. In this context, third-party apps (so-called chatbots) offer a variety of attractive functionalities that support the experience in large channels. Unfortunately, under the current permission and deployment models, chatbots in messaging systems could steal information from channels without the victim's awareness. In this paper, we propose a methodology that incorporates static and dy… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
10
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
2
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 12 publications
(10 citation statements)
references
References 28 publications
0
10
0
Order By: Relevance
“…From the systematic literature review, we have identified several articles related to security threats and vulnerabilities in chatbots. Specifically, five articles [6][7][8]10,16] were found to be related to security threats and vulnerabilities in chatbots. These articles discussed potential attacks that could compromise the security of chatbots, such as malicious input, user profiling, contextual attacks, and data breaches.…”
Section: Resultsmentioning
confidence: 99%
See 3 more Smart Citations
“…From the systematic literature review, we have identified several articles related to security threats and vulnerabilities in chatbots. Specifically, five articles [6][7][8]10,16] were found to be related to security threats and vulnerabilities in chatbots. These articles discussed potential attacks that could compromise the security of chatbots, such as malicious input, user profiling, contextual attacks, and data breaches.…”
Section: Resultsmentioning
confidence: 99%
“…For example, if a healthcare chatbot is compromised, an attacker may gain access to sensitive patient data such as medical histories, prescriptions, and other personal information. Similarly, if a finance chatbot is breached [12,13], an attacker may gain access to users' financial data, such as credit card numbers, bank account details, and transaction histories.Another important aspect of information security in chatbots is the need to maintain user trust and confidence in these systems [6][7][8][9][14][15][16][17][18]. Users must feel confident that their personal information is secure and protected when using chatbots.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations
“…This opens the door to malicious activities and gives a chance to social engineering, man-in-the-middle, and phishing attacks for compromising sensitive information like hackers use bots as tools to imitate humans to trick them into submitting their payment details [40]. The victim unknowingly trusts chatbot requests and does not know that the chatbot is controlled by a cybercriminal group, so hackers collect a large amount of personal data from users through chatbots from numerous conversations with end users every day [41].…”
Section: Ai Based Chatbots Security Threatsmentioning
confidence: 99%