Some ideas:
- How are these LLMs being used? Who is the end user and what are they using the application for?
- If a state-level threat actor wanted to compromise an LLM, how would they do it? What would their goals be? How would they then use the attack vector to accomplish their goals?
- What benefit would the actor get from doing so? What are the costs? What are the consequences if they fail or are discovered?
- How would a target detect if they’ve been compromised? How easily could they recover?