Interaction-Centric Cybersecurity Risks in LLM-Powered Dialogue Systems

Large Language Models (LLMs) have forever transformed human-AI interaction by enabling natural dialogue, reasoning, and autonomous task execution. Yet this interactioncentric paradigm introduces cybersecurity risks that traditional AI security frameworks fail to capture. This paper presents a conceptual framework and synthesis derived from a review (2015-2025) of security vulnerabilities in LLM-powered dialogue systems. We consolidate over forty studies spanning adversarial NLP, prompt injection, retrieval-augmented generation (RAG) poisoning, backdoors, and human trust exploitation. Although previous works have provided a list of isolated threats or generic LLM vulnerabilities, very few of them have looked at how interactive dialogue broadens the attack surface. Our study proposes a unified interaction-chain taxonomy distinguishing risks at input, processing, and output stages, and maps representative attacks and defenses accordingly. Drawing insights from classical adversarial literature and recent LLM surveys, we derive a layered defense pipeline integrating prompt sanitization, retrieval provenance tracking, backdoor detection, and output auditing. The resulting framework reframes cybersecurity in dialogue systems as an interactional problem bridging AI safety, NLP security, and human-computer interaction, providing a foundation for standardizing evaluation, developing cross-model benchmarks, and guiding the secure deployment of LLM agents.

Paper

Full text

PDF

Interaction-Centric Cybersecurity Risks in LLM-Powered Dialogue Systems

Semantic Scholar · 2026

Abstract

Large Language Models (LLMs) have forever transformed human-AI interaction by enabling natural dialogue, reasoning, and autonomous task execution. Yet this interactioncentric paradigm introduces cybersecurity risks that traditional AI security frameworks fail to capture. This paper presents a conceptual framework and synthesis derived from a review (2015-2025) of security vulnerabilities in LLM-powered dialogue systems. We consolidate over forty studies spanning adversarial NLP, prompt injection, retrieval-augmented generation (RAG) poisoning, backdoors, and human trust exploitation. Although previous works have provided a list of isolated threats or generic LLM vulnerabilities, very few of them have looked at how interactive dialogue broadens the attack surface. Our study proposes a unified interaction-chain taxonomy distinguishing risks at input, processing, and output stages, and maps representative attacks and defenses accordingly. Drawing insights from classical adversarial literature and recent LLM surveys, we derive a layered defense pipeline integrating prompt sanitization, retrieval provenance tracking, backdoor detection, and output auditing. The resulting framework reframes cybersecurity in dialogue systems as an interactional problem bridging AI safety, NLP security, and human-computer interaction, providing a foundation for standardizing evaluation, developing cross-model benchmarks, and guiding the secure deployment of LLM agents.

Similar papers

© 2026 NYSGPT2525 LLC