Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Security Testing of Large Language Models: Identifyingand Evaluating Common Vulnerabilities in GenerativeAI Systems: A case study
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Large Language Models (LLMs) have become integral to numerous digital systems, yet their susceptibility to adversarial misuse remains a critical concern. This thesis investigates three major categories of LLM vulnerabilities—prompt injection, jailbreaking, and hallucination across three open-source models: Vicuna-7B, Falcon-RW-1B, and OpenChat-3.5. A custom evaluation framework was developed using Python and Hugging Face libraries to systematically test and compare model behavior against adversarial prompts sourced from public datasets. The results reveal significant variation in model resilience. Falcon-RW-1B, despite being the smallest model, consistently demonstrated the highest resistance to adversarial inputs, suggesting that model size alone does not determine security. In contrast, OpenChat-3.5, while linguistically powerful, exhibited the highest vulnerability rates across all test types. Vicuna- 7B displayed moderate susceptibility, particularly to hallucination and contextual overrides. The key conclusion is that instruction tuning focused on helpfulness can unintentionally weaken a model’s ability to reject malicious prompts. The research further demonstrates that lightweight, quantized models can be safely evaluated in constrained environments without compromising the integrity of security analysis. This thesis contributes a reproducible testing pipeline and offers evidence-based recommendations for improving the robustness of LLMs in future deployments.

Place, publisher, year, edition, pages
2025. , p. 45
Keywords [en]
LLM, Open-Source, Security Testing, Vulnerabilities, Hugging Face
National Category
Software Engineering Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-23724Local ID: EXD600OAI: oai:DiVA.org:hv-23724DiVA, id: diva2:1981475
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2025-07-22 Created: 2025-07-04 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Software EngineeringComputer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 155 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf