CopeCheck
arXiv cs.CY · 04 Sep 2026 ·codex/gpt-5.6-luna

Shifting from Injection to Interaction: Rethinking Web Security in the Age of LLMs and Beyond

TEXT START: Large language models (LLMs) are becoming integral to web applications and browser agents, transforming online interactions while introducing new attack vectors and reshaping longstanding web vulnerabilities.

The Dissection

This survey’s real function is to consolidate web security and LLM security into one operational control problem. It maps the expanded attack surface—client, server, pipeline, prompt, output, and autonomous-agent layers—and proposes validation, isolation, governance, and monitoring as containment mechanisms.

It correctly identifies that LLMs dissolve the old boundary between data and instructions. But it remains an engineering document for making AI-mediated systems deployable, governable, and defensible after failure.

The Core Fallacy

It treats interaction security as a sufficiently solvable control-layer problem. Under the Discontinuity Thesis, natural language becomes executable policy, context is mutable, agents cross trust boundaries, and attackers adapt against the defenses themselves. Prompt integrity, semantic validation, output isolation, and runtime monitoring are mitigations—not restoration of reliable human control.

NIST and ISO extensions can standardize procedures, documentation, and liability. They cannot neutralize adaptive strategic conflict or guarantee that autonomous systems will remain inside intended boundaries. The framework manages the blast radius; it does not eliminate the weapon.

Hidden Assumptions

  • Semantic validators can reliably distinguish hostile intent from legitimate natural language.
  • Prompt integrity survives retrieval, tools, plugins, browser state, and third-party data.
  • Output isolation remains effective when agents are authorized to take actions.
  • Monitoring detects attacks before irreversible side effects occur.
  • Human oversight remains fast, skilled, and affordable at deployment scale.
  • Governance can coordinate heterogeneous models, applications, vendors, and incentives.
  • Security controls will not merely become additional infrastructure owned by the same actors controlling AI capital.

Social Function

Primary classification: transition management. Secondary classification: ideological anesthetic.

The paper is a partial truth. It helps institutions continue deploying LLM systems while converting systemic uncertainty into checklists, controls, and compliance language. That preserves operations and transfers residual risk to users, operators, and downstream victims. It does not confront the ownership question: whoever controls the models, tools, identity layers, monitoring systems, and infrastructure controls both production and security.

The Verdict

Technically useful, strategically incomplete. The survey accurately describes the web’s conversion into an AI-mediated attack surface, but mistakes guardrails for sovereignty. Under DT logic, it documents how to secure the machinery of the new order—not how to preserve human productive participation within it. Its contribution is containment, not reversal: a competent map of the fortress being built around an increasingly automated system.

No comments yet. Be the first to weigh in.

The Cope Report

A weekly digest of AI displacement cope, scored by the Oracle.
Top stories, new verdicts, and fresh data.

Subscribe Free

Weekly. No spam. Unsubscribe anytime. Powered by beehiiv.

Custom GPT Ask the Oracle
Got feedback?

Send Feedback