TY - GEN
T1 - Insecure Output Handling in Large Language Models (LLMs) and Approaches to Enhance Output Security, Including Prevention of LLM-Based Web Application Attacks
AU - Naik, Dishita
AU - Naik, Ishita
AU - Naik, Nitin
N1 - Copyright © 2026 The Author(s), under exclusive license to Springer Nature Switzerland AG. This version of the article has been accepted for publication, after peer review and is subject to Springer Nature’s AM terms of use [ https://www.springernature.com/gp/open-research/policies/accepted-manuscript-terms ] but is not the Version of Record and does not reflect post-acceptance improvements, or any corrections. The Version of Record is available online at: https://doi.org/10.1007/978-3-032-16791-0_33
PY - 2026/5/17
Y1 - 2026/5/17
N2 - Large Language Models (LLMs) are rapidly becoming integral components of an unlimited number of intelligent systems and web applications due to their extraordinary versatility, scalability, and ability to handle complex language-driven tasks across domains. However, insecure output handling in LLMs can significantly undermine the secure and safe integration of LLMs into intelligent systems and web applications by introducing vulnerabilities that may lead to unintended behaviour, security breaches, and system-level or application-level exploits. Moreover, this opens the door for LLM-based web application attacks where the insecure or malicious output of the LLM is exploited for an LLM-integrated downstream web system or application that processes this insecure or malicious output. The successful and secure integration of LLMs into intelligent systems and web applications depends on several factors, including the secure handling of LLM outputs to mitigate potential vulnerabilities and prevent attacks on LLM-integrated web systems or applications. This highlights the importance of LLM outputs and their secure and safe utilisation in LLM-integrated web systems and applications, alongside the critical role of input prompts, training data, and underlying AI models in ensuring their overall security and safety. Therefore, this paper will examine insecure output handling in LLMs and its consequences including LLM-based web application attacks. Initially, it will explain insecure output handling and LLM-based web application attacks. Next, it will examine the most common types of LLM-based web application attacks, where each type will cover associated attack vectors and distinction from other types of LLM-based web application attacks. Subsequently, it will examine several risks associated with LLM-based web application attacks. Finally, it will discuss several approaches to enhance output security, including prevention of LLM-based web application attacks.
AB - Large Language Models (LLMs) are rapidly becoming integral components of an unlimited number of intelligent systems and web applications due to their extraordinary versatility, scalability, and ability to handle complex language-driven tasks across domains. However, insecure output handling in LLMs can significantly undermine the secure and safe integration of LLMs into intelligent systems and web applications by introducing vulnerabilities that may lead to unintended behaviour, security breaches, and system-level or application-level exploits. Moreover, this opens the door for LLM-based web application attacks where the insecure or malicious output of the LLM is exploited for an LLM-integrated downstream web system or application that processes this insecure or malicious output. The successful and secure integration of LLMs into intelligent systems and web applications depends on several factors, including the secure handling of LLM outputs to mitigate potential vulnerabilities and prevent attacks on LLM-integrated web systems or applications. This highlights the importance of LLM outputs and their secure and safe utilisation in LLM-integrated web systems and applications, alongside the critical role of input prompts, training data, and underlying AI models in ensuring their overall security and safety. Therefore, this paper will examine insecure output handling in LLMs and its consequences including LLM-based web application attacks. Initially, it will explain insecure output handling and LLM-based web application attacks. Next, it will examine the most common types of LLM-based web application attacks, where each type will cover associated attack vectors and distinction from other types of LLM-based web application attacks. Subsequently, it will examine several risks associated with LLM-based web application attacks. Finally, it will discuss several approaches to enhance output security, including prevention of LLM-based web application attacks.
KW - AI models
KW - Cross-Site Request Forgery (CSRF) Attacks
KW - Cross-Site Scripting (XSS) Attacks
KW - Extensible Markup Language (XML) Injection Attacks
KW - Generative AI
KW - Insecure output handling in LLMs
KW - LLM-based web application attacks
KW - LLMs
KW - Large Language Models
KW - Server-Side Request Forgery (SSRF) Attacks
KW - Structured Query Language Injection (SQLi) Attacks
UR - https://link.springer.com/chapter/10.1007/978-3-032-16791-0_33
UR - https://www.scopus.com/pages/publications/105040541445
U2 - 10.1007/978-3-032-16791-0_33
DO - 10.1007/978-3-032-16791-0_33
M3 - Conference publication
SN - 9783032167903
T3 - Lecture Notes in Networks and Systems (LNNS)
SP - 695
EP - 720
BT - Contributions Presented at the International Conference on Computing, Communication, Cybersecurity & AI, July 10–11, 2025, Birmingham, UK
A2 - Naik, Nitin
A2 - Jenkins, Paul
A2 - Prajapat, Shaligram
A2 - Grace, Paul
PB - Springer, Cham
ER -