Analisis Kerentanan Keamanan Chatbot Berbasis Large Language Model Terhadap Serangan SQL Injection

Authors

  • Bambang Harie Wiyono Sekolah Tinggi Teknologi Terpadu Nurul Fikri
  • Filia Nur Anjaini Sekolah Tinggi Teknologi Terpadu Nurul Fikri
  • Lukman Rosyidi Sekolah Tinggi Teknologi Terpadu Nurul Fikri

DOI:

https://doi.org/10.52158/qy05dk06

Keywords:

Large Language Model (LLM), Prompt Injection, SQL Injection, Black-box Penetration Testing, Cybersecurity

Abstract

Perkembangan teknologi Large Language Model (LLM) telah mendorong pemanfaatan chatbot pada berbagai layanan digital. Integrasi chatbot dengan basis data dan layanan backend berpotensi menimbulkan risiko keamanan, terutama terhadap serangan SQL Injection. Penelitian ini bertujuan untuk menganalisis dan menguji kerentanan SQL Injection pada aplikasi chatbot berbasis LLM. Pengujian dilakukan menggunakan payload SQL Injection, Burp Suite, dan OWASP ZAP pada empat chatbot berbasis LLM, yaitu AlexAI, Gemini, Claude, dan Dola. Hasil penelitian menunjukkan bahwa seluruh target tidak memperlihatkan indikasi keberhasilan eksploitasi, tidak terjadi kebocoran informasi, serta tidak ditemukan akses tidak sah ke basis data. Meskipun demikian, ditemukan beberapa isu keamanan pada tingkat aplikasi yang berkaitan dengan konfigurasi keamanan web. Temuan ini menunjukkan bahwa keamanan chatbot berbasis LLM tidak hanya bergantung pada ketahanan model, tetapi juga pada keamanan aplikasi dan infrastruktur pendukung yang digunakan.

References

Michael R. King, “A Conversation on Artificial Intelligence, Chatbots, and Plagiarism in Higher Education,” National Library of Medicine, vol. 16, no. 1, pp. 1–2, Feb. 2023, doi: 10.1007/s12195-022-00754-8.

Jeong Hyun Park et al., “AI and Creativity in Entrepreneurship Education: A Systematic Review of LLM Applications,” AI, vol. 6, no. 5, pp. 1–22, May 2025, doi: 10.3390/ai6050100.

Mohammed Amine et al., “From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows,” ICT Express, pp. 1–36, Dec. 2025, doi: 10.1016/j.icte.2025.12.001.

Zhiyu Liao et al., “Attack and Defense Techniques in Large Language Models: A Survey and New Perspectives,” Neural Networks, Apr. 2026, doi: 10.1016/j.neunet.2025.108388.

Yi Liu et al., “Prompt Injection Attack Against LLM-Integrated Applications,” arXiv, Dec. 2024. Available: http://arxiv.org/abs/2306.05499

Sippo Rossi et al., “An Early Categorization of Prompt Injection Attacks on Large Language Models,” arXiv, Jan. 2024. Available: http://arxiv.org/abs/2402.00898

Rodrigo Pedro et al., “Prompt to SQL Injections in LLM-Integrated Web Applications: Risks and Defenses,” Proceedings of the International Conference on Software Engineering (ICSE), pp. 1768–1780, Apr. 2025, doi: 10.1109/ICSE55347.2025.00007.

Enyoung Kim and Sangkyun Lee, “SQL Injection in LLM-Generated Queries: Systematic Analysis of Detection Gaps and Security Risks,” IEEE Access, vol. 14, 2026, doi: 10.1109/ACCESS.2026.3654822.

M. Lin et al., “Are Your LLM-Based Text-to-SQL Models Secure? Exploring SQL Injection via Backdoor Attacks,” Computer Science Cryptography and Security, 2025, doi: 10.1145/3769762.

Farzad et al., “When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications,” SCITEPRESS, vol. 2, pp. 1380–1390, 2026, doi: 10.5220/0014300000004052.

Miles Q. Li, Benjamin C. M. Fung, “Security Concerns for Large Language Models: A Survey,” Journal of Information Security and Applications, Nov. 2025, doi: 10.1016/j.jisa.2025.104284.

Qianlog Lan, Anuj Kaul, and Shaun Jones, “Prompt Injection Detection in LLM Integrated Applications,” International Journal of Network Dynamics and Intelligence, vol. 4, no. 2, 2025, doi: 10.53941/ijndi.2025.100013.

Mohammed Alamsabi, Michael Tchuindjang, and Sarfraz Brohi, “Embedding-Based Detection of Indirect Prompt Injection Attacks in Large Language Models Using Semantic Context Analysis,” Algorithms, vol. 19, no. 1, 2026, doi: 10.3390/a19010092.

Zhilong et al., “To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt,” Proceedings of the 55th IEEE/IFIP International Conference on Dependable Systems and Networks (DSN-S), pp. 22–28, Jun. 2025, doi: 10.1109/DSN-S65789.2025.00037.

Zhexin Zhang et al., “Defending Large Language Models Against Jailbreaking Attacks Through Goal Prioritization,” Proceedings of the Annual Meeting of the Association for Computational Linguistics (ACL), vol. 1, pp. 8865–8887, Jun. 2024, doi: 10.18653/v1/2024.acl-long.481.

Edoardo et al., “AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents,” Advances in Neural Information Processing Systems (NeurIPS), vol. 37, Oct. 2024, doi: 10.52202/079017-2636.

Jeremy McHugh et al., “Prompt Injection 2.0: Hybrid AI Threats,” arXiv, Jul. 2025. Available: http://arxiv.org/abs/2507.13169

Patrick Chao et al., “JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models,” Advances in Neural Information Processing Systems (NeurIPS), vol. 37, pp. 1–25, Nov. 2024, doi: 10.52202/079017-1745.

Apostol et al., “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations,” NIST Technical Series, Mar. 2025, doi: 10.6028/NIST.AI.100-2e2025.

Rodrigo Pedro et al., “From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?,” arXiv, Jan. 2025. Available: http://arxiv.org/abs/2308.01990

Downloads

Published

2026-06-30

How to Cite

Analisis Kerentanan Keamanan Chatbot Berbasis Large Language Model Terhadap Serangan SQL Injection. (2026). Journal of Applied Smart Electrical Network and Systems, 7(1), 27-39. https://doi.org/10.52158/qy05dk06