paper-with-me

홈 › Papers

When RAG Chatbots Expose Their Backend: An Anonymized Case Study of Privacy and Security Risks in Patient-Facing Medical AI

2026-05-01 · Alfredo Madrid-García, Miguel Rujas arxiv

Background: Patient-facing medical chatbots based on retrieval-augmented generation (RAG) are increasingly promoted to deliver accessible, grounded health information. AI-assisted development lowers the barrier to building them, but they still demand rigorous security, privacy, and governance controls. Objective: To report an anonymized, non-destructive security assessment of a publicly accessible patient-facing medical RAG chatbot and identify governance lessons for safe deployment of generative AI in health. Methods: We used a two-stage strategy. First, Claude Opus 4.6 supported exploratory prompt-based testing and structured vulnerability hypotheses. Second, candidate findings were manually verified using Chrome Developer Tools, inspecting browser-visible network traffic, payloads, API schemas, configuration objects, and stored interaction data. Results: The LLM-assisted phase identified a critical vulnerability: sensitive system and RAG configuration appeared exposed through client-server communication rather than restricted server-side. Manual verification confirmed that ordinary browser inspection allowed collection of the system prompt, model and embedding configuration, retrieval parameters, backend endpoints, API schema, document and chunk metadata, knowledge-base content, and the 1,000 most recent patient-chatbot conversations. The deployment also contradicted its privacy assurances: full conversation records, including health-related queries, were retrievable without authentication. Conclusions: Serious privacy and security failures in patient-facing RAG chatbots can be identified with standard browser tools, without specialist skills or authentication; independent review should be a prerequisite for deployment. Commercial LLMs accelerated this assessment, including under a false developer persona; assistance available to auditors is equally available to adversaries.

📄 PDF Abstract BibTeX arXiv:2605.00796

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Low-code from frontend to backend: Connecting conversational user interfaces to backend services via a low-code IoT platform

2024-09-13 · Irene Weber

Current chatbot development platforms and frameworks facilitate setting up the language and dialog part of chatbots, while connecting it to backend services and business functions requires substantial manual coding effor…

Chatbot

A Crowdsourced Study of ChatBot Influence in Value-Driven Decision Making Scenarios

2025-11-19 · Anthony Wise, Xinyi Zhou, Martin Reimann, Anind Dey 외 arxiv

Similar to social media bots that shape public opinion, healthcare and financial decisions, LLM-based ChatBots like ChatGPT can persuade users to alter their behavior. Unlike prior work that persuades via overt-partisan …

Decision Making

PromptDecipher: Supporting AI Tutor Authoring Through Editable Simulated Interactions

2026-05-15 · Miina Koyama, Ruiwei Xiao, John Stamper arxiv

Chatbots have long been explored as tools to support learning, and recent advances in large language models have significantly expanded the availability of platforms for educators to author AI tutoring chatbots. Yet effe…

Deep Reinforcement Learning for Chatbots Using Clustered Actions and Human-Likeness Rewards

2019-08-27 · Heriberto Cuayáhuitl, Donghyeon Lee, Seonghan Ryu, Sungja Choi 외

Training chatbots using the reinforcement learning paradigm is challenging due to high-dimensional states, infinite action spaces and the difficulty in specifying the reward function. We address such problems using clust…

Deep Reinforcement Learningreinforcement-learningReinforcement LearningReinforcement Learning (RL)+3

The Fire Thief Is Also the Keeper: Balancing Usability and Privacy in Prompts

2024-06-20 · Zhili Shen, Zihang Xi, Ying He, Wei Tong 외

The rapid adoption of online chatbots represents a significant advancement in artificial intelligence. However, this convenience brings considerable privacy concerns, as prompts can inadvertently contain sensitive inform…

Code GenerationQuestion AnsweringText Summarization