Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
2023/02/23 by Kai Greshake, Greshake, Kai, Sahar Abdelnabi +9 · 10 voices · 253 citations
Computer Science · Social Sciences · #Access Control and Trust #Topic Modeling #Web Application Security Vulnerabilities #cs.AI #cs.CL #cs.CR #cs.CY
paper · pdf · doi:10.48550/arxiv.2302.12173
openalex publication_date 2023/02/23 · openalex created_date 2023/02/25 · openalex updated_date 2026/07/28
Abstract
Large Language Models (LLMs) are increasingly being integrated into applications, with versatile functionalities that can be easily modulated via natural language prompts. So far, it was assumed that the user is directly prompting the LLM. But, what if it is not the user prompting? We show that LLM-Integrated Applications blur the line between data and instructions and reveal several new attack vectors, using Indirect Prompt Injection, that enable adversaries to remotely (i.e., without a direct interface) exploit LLM-integrated applications by strategically injecting prompts into data likely to be retrieved at inference time. We derive a comprehensive taxonomy from a computer security perspective to broadly investigate impacts and vulnerabilities, including data theft, worming, information ecosystem contamination, and other novel security risks. We then demonstrate the practical viability of our attacks against both real-world systems, such as Bing Chat and code-completion engines, and GPT-4 synthetic applications. We show how processing retrieved prompts can act as arbitrary code execution, manipulate the application's functionality, and control how and if other APIs are called. Despite the increasing reliance on LLMs, effective mitigations of these emerging threats are lacking. By raising awareness of these vulnerabilities, we aim to promote the safe and responsible deployment of these powerful models and the development of robust defenses that protect users from potential attacks.
Cited by
- Ground Truth First: A Longitudinal Evaluation Instrument for Agent Memory, and the Tenure Crossover in Memory-Architecture Rankings
- ASEval: Automated Trajectory-Level Security Testing for Autonomous Agents
- Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense
- ToolGuardian: Declarative Security for AI Agent-Tool Interactions
- PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses
- Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents
- HijackKV: New Threat in Position-Independent KV Cache Reuse
- Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents
- Will the Agent Recuse, and Will It Stop? Measuring LLM-Agent Compliance with In-Band Governance Signals at the Access Door and Mid-Flight
- The safety failures we are not instrumenting: a perspective on hidden safety-critical challenges in modern AI systems
- IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests
- Twin Agent: Context Residual Compression for Privilege Separated Agents
- Falsifiable Release Gates for Self-Improving Systems: Standing Invariants at Scale
- Find Before You Fine-Tune: A Diagnostic Study of Small LLMs for Cybersecurity QA
- Real-World Evaluation of an AI Agent Drafting Translational Impact Summaries
- Guardrails as Scapegoats: Auditing Unfaithful Safety Refusals in Tool-Augmented LLM Agents
- Data Leakage Prevention in Agentic Applications via Preemptive Hardening
- PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents
- Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security
- ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems
- Adversarial Pragmatics for AI Safety Evaluation: A Diagnostic Framework and Seed Benchmark for Language-Mediated Control
- RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control
- Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?
- Trusted Credentials, Untrusted Behavior: Benchmarking LLM-Agent Security in High-Performance Computing
- The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI
- When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift
- Understanding How University Guidelines Address Privacy and Security Issues of Generative AI in Academic Settings
- DisarmRAG: Stealthy Retriever-Centric Poisoning to Disable Self-Correction in Retrieval-Augmented Generation (Extended Version)
- How Do You Choose Your AI Component? An Interview Study of Secure AI Integration in Practice
- AgentRedBench: Dynamic Redteaming and Integration-Aware Defense for LLM Agents over SaaS Integrations
- Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives
- AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems
- Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation Evaluation
- Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents
- Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems
- It is not enough to give your moderation rules to ChatGPT: Policy-as-Prompt Moderation and Its Potential Impacts on Community Governance
- Ghost Vectors: Soft-Deleted Embeddings Remain Reconstructible in HNSW Vector Databases
- Stateful Guardrails for Multi-Turn LLM Systems: A Conversational Risk Accumulation Framework
- The End of Code Review: Coding Agents Supersede Human Inspection
- NEXUS: Structured Runtime Safety for Tool-Using LLM Agents
- Incomplete Prompt Jailbreaks in Large Language Models
- Blind Spots in the Guard: How Domain-Camouflaged Injection Attacks Evade Detection in Multi-Agent LLM Systems
- Multi-Stream LLMs: Unblocking Language Models with Parallel Streams of Thoughts, Inputs and Outputs
- TopoGuard: Graph Theory Based Defenses Against Split-Knowledge Attacks on RAG
- Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection
- Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
- Distributional AGI Safety
- A Red Teaming Framework for Large Language Models: A Case Study on Faithfulness Evaluation
- Securing AI Agents with Information-Flow Control
- Exploiting large language models in peer review: indirect prompt injection attacks and integrity probes
- Cats Confuse Reasoning LLM: Query Agnostic Adversarial Triggers for Reasoning Models
- Measuring Epistemic Resilience of LLMs Under Misleading Medical Context
- Prismata: Confining Cross-Site Prompt Injection in Web Agents
- Agent Security is a Systems Problem
- Multilingual Hidden Prompt Injection Attacks on LLM-Based Academic Reviewing
- Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents
- Agent Data Injection Attacks are Realistic Threats to AI Agents
- Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric
- Where Is the Cost of Third-Party API Routers in Agentic Software Development?
- Isolated but Exposed: Persistence-Based Memory Extraction Attack on LLM Agents
- ActPlane: Programmable OS-Level Policy Enforcement for Agent Harnesses
- TriShieldRAG: A Three-Ring Defense-in-Depth Framework Against Knowledge Corruption in Retrieval-Augmented Generation
- Agentic Cloud Decoys: A Deception-Driven Framework for Autonomous Intrusion Investigation
- Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales
- ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents
- Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response
- The Missing Layer: Specification Infrastructure for AI Oversight
- False Prophets: On the Security of World Models in Agentic Systems
- How Do Practitioners Build SE Agents? Insights from a Mixed-Methods Study
- Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents
- Decentralized Granular Access Control for Agentic AI Systems in Critical Infrastructure
- WIRE: Profiling Witnessed Within-Policy Instruction Collisions in LLM Agents
- PINA: Prompt Injection Attack Against Navigation Agents
- Exploring the Security Threats of Retriever Backdoors in Retrieval-Augmented Code Generation
- Casting a SPELL: Sentence Pairing Exploration for LLM Limitation-breaking
- Beyond Context: Large Language Models Failure to Grasp Users Intent
- DREAM: Dynamic Red-teaming across Environments for AI Models
- SecureCode: A Production-Grade Multi-Turn Dataset for Training Security-Aware Code Generation Models
- Differences That Matter: Auditing Models for Capability Gap Discovery and Rectification
- Agent Tools Orchestration Leaks More: Dataset, Benchmark, and Mitigation
- Penetration Testing of Agentic AI: A Comparative Security Analysis Across Models and Frameworks
- IntentMiner: Intent Inversion Attack via Tool Call Analysis in the Model Context Protocol
- Reasoning-Style Poisoning of LLM Agents via Stealthy Style Transfer: Process-Level Attacks and Runtime Monitoring in RSV Space
- Detecting Prompt Injection Attacks Against Application Using Classifiers
- MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents
- When Reject Turns into Accept: Quantifying the Vulnerability of LLM-Based Scientific Reviewers to Indirect Prompt Injection
- How to Trick Your AI TA: A Systematic Study of Academic Jailbreaking in LLM Code Evaluation
- Phishing Email Detection Using Large Language Models
- ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
- Black-Box Behavioral Distillation Breaks Safety Alignment in Medical LLMs
- Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
- Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem
- MIRAGE: Misleading Retrieval-Augmented Generation via Black-box and Query-agnostic Poisoning Attacks
- SoK: Trust-Authorization Mismatch in LLM Agent Interactions
- Cognitive Control Architecture (CCA): A Lifecycle Supervision Framework for Robustly Aligned AI Agents
- Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks
- ProSocialAlign: Preference Conditioned Test Time Alignment in Language Models
- Reflection-Satisfaction Tradeoff: Investigating Impact of Reflection on Student Engagement with AI-Generated Programming Hints
- Personalizing Agent Privacy Decisions via Logical Entailment
- Counterfeit Answers: Adversarial Forgery against OCR-Free Document Visual Question Answering
- Context-Aware Hierarchical Learning: A Two-Step Paradigm towards Safer LLMs
- Evaluating the Robustness of Large Language Model Safety Guardrails Against Adversarial Attacks
- EmoRAG: Evaluating RAG Robustness to Symbolic Perturbations
- Systems Security Foundations for Agentic Computing
- Mitigating Indirect Prompt Injection via Instruction-Following Intent Analysis
- Bias Injection Attacks on RAG Databases and Sanitization Defenses
- Toward a Safe Internet of Agents
- An Empirical Study on the Security Vulnerabilities of GPTs
- AgentShield: Make MAS more secure and efficient
- BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents
- AttackPilot: Autonomous Inference Attacks Against ML Services With LLM-Based Agents
- Strategic Decision Framework for Enterprise LLM Adoption
- MURMUR: Using cross-user chatter to break collaborative language agents in groups
- Taxonomy, Evaluation and Exploitation of IPI-Centric LLM Agent Defense Frameworks
- Can MLLMs Detect Phishing? A Comprehensive Security Benchmark Suite Focusing on Dynamic Threats and Multimodal Evaluation in Academic Environments
- SnapAudit: Active Auditing of Differentially Private In-Context Learning via Snapshot-Based Simulation
- Securing Generative AI in Healthcare: A Zero-Trust Architecture Powered by Confidential Computing on Google Cloud
- Data Poisoning Vulnerabilities Across Healthcare AI Architectures: A Security Threat Analysis
- Automatic Minds: Cognitive Parallels Between Hypnotic States and Large Language Model Processing
- Large Language Models for Agentic NetOps and AIOps: Architectures, Evaluation, and Safety
- Injecting Falsehoods: Adversarial Man-in-the-Middle Attacks Undermining Factual Recall in LLMs
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
- ConVerse: Benchmarking Contextual Safety in Agent-to-Agent Conversations
- TAMAS: Benchmarking Adversarial Risks in Multi-Agent LLM Systems
- Caption Injection for Optimization in Generative Search Engine
- Prevalence of Security and Privacy Risk-Inducing Usage of AI-based Conversational Agents
- Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels
- SkillGate: Cost Efficient Runtime Malicious Skill File Detection in Coding Agents
- Distributing Security Controls Through Harness Engineering
- Cache Merging as a Convergent Replicated State for Multi-Agent Latent Reasoning
- GPT-Red: Automated Red Teaming via Self-Play at Scale
- Towards Trustworthy Embodied Intelligence: A Systems Framework and Graded Trustworthiness Levels
- Safety from Honesty in a Disinterested AI Predictor
- The Capability Paradox: How Smarter Auditors Make Multi-Agent Systems Less Secure
- The Consensus Trap: Rescuing Multi-Agent LLMs from Adversarial Majorities via Token-Level Collaboration
- Toward Understanding Security Issues in the Model Context Protocol Ecosystem
- The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
- Agents at Risk: How Users Unwittingly Undermine LLM Safety
- Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges
- QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
- MCPGuard : Automatically Detecting Vulnerabilities in MCP Servers
- Is Your Prompt Poisoning Code? Defect Induction Rates and Security Mitigation Strategies
- Breaking Agent Backbones: Evaluating the Security of Backbone LLMs in AI Agents
- PaperAsk: A Benchmark for Reliability Evaluation of LLMs in Paper Search and Reading
- Securing AI Agent Execution
- NeuroGenPoisoning: Neuron-Guided Attacks on Retrieval-Augmented Generation of LLM via Genetic Optimization of External Knowledge
- Soft Instruction De-escalation Defense
- AegisMCP: Online Graph Intrusion Detection for Tool-Augmented LLMs on Edge Devices
- Defending Against Prompt Injection with DataFilter
- The Trust Paradox in LLM-Based Multi-Agent Systems: When Collaboration Becomes a Security Vulnerability
- Investigating the Impact of Dark Patterns on LLM-Based Web Agents
- Breaking and Fixing Defenses Against Control-Flow Hijacking in Multi-Agent Systems
- Black-box Optimization of LLM Outputs by Asking for Directions
- MAGPIE: A benchmark for Multi-AGent contextual PrIvacy Evaluation
- Terrarium: Revisiting the Blackboard for Multi-Agent Safety, Privacy, and Security Studies
- Formalizing the Safety, Security, and Functional Properties of Agentic AI Systems
- PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
- Keep Calm and Avoid Harmful Content: Concept Alignment and Latent Manipulation Towards Safer Answers
- Guarding the Guardrails: A Taxonomy-Driven Approach to Jailbreak Detection
- PromptLocate: Localizing Prompt Injection Attacks
- Attacks by Content: Automated Fact-checking is an AI Security Issue
- RAG-Pull: Imperceptible Attacks on RAG Systems for Code Generation
- A Vision for Access Control in LLM-based Agent Systems
- BlackIce: A Containerized Red Teaming Toolkit for AI Security Testing
- MetaBreak: Jailbreaking Online LLM Services via Special Token Manipulation
- ADMIT: Few-shot Knowledge Poisoning Attacks on RAG-based Fact Checking
- SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents
- Red-Teaming the Agentic Red-Team
- Who Owns This Agent? Tracing AI Agents Back to Their Owners
- SoK: Security of Autonomous LLM Agents in Agentic Commerce
- Adversarial News and Lost Profits: Manipulating Headlines in LLM-Driven Algorithmic Trading
- The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
- Exploiting Web Search Tools of AI Agents for Data Exfiltration
- SeCon-RAG: A Two-Stage Semantic Filtering and Conflict-Free Framework for Trustworthy RAG
- CommandSans: Securing AI Agents with Surgical Precision Prompt Sanitization
- Chain-of-Trigger: An Agentic Backdoor that Paradoxically Enhances Agentic Robustness
- Intelligent AI Delegation
- Bypassing Prompt Guards in Production with Controlled-Release Prompting
- A Survey on Agentic Security: Applications, Threats and Defenses
- Deterministic Legal Agents: A Canonical Primitive API for Auditable Reasoning over Temporal Knowledge Graphs
- Adversarial Reinforcement Learning for Large Language Model Agent Safety
- Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?
- RL Is a Hammer and LLMs Are Nails: A Simple Reinforcement Learning Recipe for Strong Prompt Injection
- AgentTypo: Adaptive Typographic Prompt Injection Attacks against Black-box Multimodal Agents
- Microsaccade-Inspired Probing: Positional Encoding Perturbations Reveal LLM Misbehaviours
- Better Privilege Separation for Agents by Restricting Data Types
- Fingerprinting LLMs via Prompt Injection
- SecInfer: Preventing Prompt Injection via Inference-time Scaling
- GSPR: Aligning LLM Safeguards as Generalizable Safety Policy Reasoners
- Takedown: How It's Done in Modern Coding Agent Exploits
- Incentive-Aligned Multi-Source LLM Summaries
- ReliabilityRAG: Effective and Provably Robust Defense for RAG-based Web-Search
- FinVault: Benchmarking Financial Agent Safety in Execution-Grounded Environments
- ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents
- Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools
- RAG Security and Privacy: Formalizing the Threat Model and Attack Surface
- A Framework for Rapidly Developing and Deploying Protection Against Large Language Model Attacks
- Investigating Security Implications of Automatically Generated Code on the Software Supply Chain
- Stop Shipping AI Agents on Faith: Capability Is Not Production Readiness
- Security of World-Model-Based Embodied AI: A Lifecycle of Threats, Defenses, and Evaluation
- Piggybacking on Perception: Stealthy Concurrent Audio Prompt Injections against Multimodal LLM Agents
- What If Prompt Injection Never Left? Rethinking Agent Security through Cross-Session Stored Prompt Injection
- AI Agents May Always Fall for Prompt Injections
- Image-based Prompt Injection: Hijacking Multimodal LLMs through Visually Embedded Adversarial Instructions
- Pressure Reveals Character: Behavioural Alignment Evaluation at Depth
- PhantomLint: Principled Detection of Hidden LLM Prompts in Structured Documents
- Attacking LLMs and AI Agents: Advertisement Embedding Attacks Against Large Language Models
- D-REX: A Benchmark for Detecting Deceptive Reasoning in Large Language Models
- MUSE: MCTS-Driven Red Teaming Framework for Enhanced Multi-Turn Dialogue Safety in Large Language Models
- Enterprise AI Must Enforce Participant-Aware Access Control
- AQUA-LLM: Evaluating Accuracy, Quantization, and Adversarial Robustness Trade-offs in LLMs for Cybersecurity Question Answering
- A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
- MillStone: How Open-Minded Are LLMs?
- Phi: Preference Hijacking in Multi-modal Large Language Models at Inference Time
- From Firewalls to Frontiers: AI Red-Teaming is a Domain-Specific Evolution of Cyber Red-Teaming
- Free-MAD: Consensus-Free Multi-Agent Debate
- LLM in the Middle: A Systematic Review of Threats and Mitigations to Real-World LLM-based Systems
- When Your Reviewer is an LLM: Biases, Divergence, and Prompt Injection Risks in Peer Review
- AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents
- SoK: Security and Privacy of AI Agents for Blockchain
- Preventing Another Tessa: Modular Safety Middleware For Health-Adjacent AI Assistants
- EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System
- AntiDote: Bi-level Adversarial Training for Tamper-Resistant LLMs
- BinaryShield: Cross-Service Threat Intelligence in LLM Services using Privacy-Preserving Fingerprints
- Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
- Breaking to Build: A Threat Model of Prompt-Based Attacks for Securing LLMs
- Manipulating Transformer-Based Models: Controllability, Steerability, and Robust Interventions
- Adversarial Bug Reports as a Security Risk in Language Model-Based Automated Program Repair
- MEUV: Achieving Fine-Grained Capability Activation in Large Language Models via Mutually Exclusive Unlock Vectors
- A Comprehensive Survey on Trustworthiness in Reasoning with Large Language Models
- Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain
- A Survey: Towards Privacy and Security in Mobile Large Language Models
- The Aegis Protocol: A Foundational Security Framework for Autonomous AI Agents
- IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents
- Inducing State Anxiety in LLM Agents Reproduces Human-Like Biases in Consumer Decision-Making
- The Resurgence of GCG Adversarial Attacks on Large Language Models
- Rethinking Testing for LLM Applications: Characteristics, Challenges, and a Lightweight Interaction Protocol
- Servant, Stalker, Predator: How An Honest, Helpful, And Harmless (3H) Agent Unlocks Adversarial Skills
- Reliable Weak-to-Strong Monitoring of LLM Agents
- UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation
- CIA+TA Risk Assessment for AI Reasoning Vulnerabilities
- MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
- LumiMAS: A Comprehensive Framework for Real-Time Monitoring and Enhanced Observability in Multi-Agent Systems
- Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous
- Role-Augmented Intent-Driven Generative Search Engine Optimization
- Securing Educational LLMs: A Generalised Taxonomy of Attacks on LLMs and DREAD Risk Assessment
- AI Security Map: Holistic Organization of AI Security Technologies and Impacts on Stakeholders
- When AIOps Become "AI Oops": Subverting LLM-driven IT Operations via Telemetry Manipulation
- Evo-MARL: Co-Evolutionary Multi-Agent Reinforcement Learning for Internalized Safety
- AttnTrace: Attention-based Context Traceback for Long-Context LLMs
- The SMeL Test: A simple benchmark for media literacy in language models
- A Survey on Data Security in Large Language Models
- LeakSealer: A Semisupervised Defense for LLMs Against Prompt Injection and Leakage Attacks
Discussions
- Compromising LLM-integrated applications with indirect prompt injection [hn, 43 points, 20 comments]
- Novel Prompt Injection Threats to Application-Integrated Large Language Models [hn, 8 points, 2 comments]
- Getting more than what you've asked for: The Next Stage of Prompt Engineering [hn, 6 points, 1 comments]
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection [lobsters, 4 points, 0 comments]
- they cite this paper on AI agent hacking via "indirect prompt injection" [bsky, 2 points, 0 comments]
- Novel Prompt Injection Threats to Application-Integrated Large Language Models [hn, 1 points, 0 comments]
- I'm just going to leave this here... arxiv.org/abs/2302.12173 [bsky, 0 points, 0 comments]
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection https://arxiv.org/abs/2302.12173 [bsky, 0 points, 0 comments]
- - Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Ma [bsky, 0 points, 1 comments]
- "Compromising Real-WorldLLM-Integrated Applications with Indirect Prompt Injection" arxiv.org/pdf/2302.12173 [bsky, 0 points, 0 comments]
Related