Access control attacks test whether AI systems properly enforce authorization boundaries. This includes broken object-level authorization (BOLA), broken function-level authorization (BFLA), debug mode activation, and session hijacking. These are classic web security vulnerabilities adapted for AI systems, and they remain some of the most commonly exploited flaws.

Summary

4 attacks total: 3 single-turn, 1 multi-turn.

Attacks

Example