System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
Fuente:
arXiv
Salvato in:
| Autori principali: | Li, Zongze, Guo, Jiawei, Cai, Haipeng |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
PIDP-Attack: Combining Prompt Injection with Database Poisoning Attacks on Retrieval-Augmented Generation Systems
di: Wang, Haozhen, et al.
Pubblicazione: (2026)
di: Wang, Haozhen, et al.
Pubblicazione: (2026)
Prompt Injection Attacks on Large Language Models in Oncology
di: Clusmann, Jan, et al.
Pubblicazione: (2024)
di: Clusmann, Jan, et al.
Pubblicazione: (2024)
Goal-guided Generative Prompt Injection Attack on Large Language Models
di: Zhang, Chong, et al.
Pubblicazione: (2024)
di: Zhang, Chong, et al.
Pubblicazione: (2024)
Evaluation of Prompt Injection Defenses in Large Language Models
di: Deep, Priyal, et al.
Pubblicazione: (2026)
di: Deep, Priyal, et al.
Pubblicazione: (2026)
PromptLocate: Localizing Prompt Injection Attacks
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models
di: Shan, Shawn, et al.
Pubblicazione: (2023)
di: Shan, Shawn, et al.
Pubblicazione: (2023)
Enhancing Prompt Injection Attacks to LLMs via Poisoning Alignment
di: Shao, Zedian, et al.
Pubblicazione: (2024)
di: Shao, Zedian, et al.
Pubblicazione: (2024)
Persona Attack: Incremental Memory Injection Jailbreak Attack against Large Language Models
di: Park, Junyoung, et al.
Pubblicazione: (2026)
di: Park, Junyoung, et al.
Pubblicazione: (2026)
WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
di: Evtimov, Ivan, et al.
Pubblicazione: (2025)
di: Evtimov, Ivan, et al.
Pubblicazione: (2025)
Prompt Injection as an Emerging Threat: Evaluating the Resilience of Large Language Models
di: Ganiuly, Daniyal, et al.
Pubblicazione: (2025)
di: Ganiuly, Daniyal, et al.
Pubblicazione: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
di: Zhu, Kaijie, et al.
Pubblicazione: (2025)
di: Zhu, Kaijie, et al.
Pubblicazione: (2025)
Securing AI Agents Against Prompt Injection Attacks
di: Ramakrishnan, Badrinath, et al.
Pubblicazione: (2025)
di: Ramakrishnan, Badrinath, et al.
Pubblicazione: (2025)
Analysis of LLMs Against Prompt Injection and Jailbreak Attacks
di: Jaiswal, Piyush, et al.
Pubblicazione: (2026)
di: Jaiswal, Piyush, et al.
Pubblicazione: (2026)
Turning Generative Models Degenerate: The Power of Data Poisoning Attacks
di: Jiang, Shuli, et al.
Pubblicazione: (2024)
di: Jiang, Shuli, et al.
Pubblicazione: (2024)
Token-Efficient Prompt Injection Attack: Provoking Cessation in LLM Reasoning via Adaptive Token Compression
di: Cui, Yu, et al.
Pubblicazione: (2025)
di: Cui, Yu, et al.
Pubblicazione: (2025)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models
di: Xiong, Junjie, et al.
Pubblicazione: (2025)
di: Xiong, Junjie, et al.
Pubblicazione: (2025)
VPI-Bench: Visual Prompt Injection Attacks for Computer-Use Agents
di: Cao, Tri, et al.
Pubblicazione: (2025)
di: Cao, Tri, et al.
Pubblicazione: (2025)
Multimodal Prompt Injection Attacks: Risks and Defenses for Modern LLMs
di: Yeo, Andrew, et al.
Pubblicazione: (2025)
di: Yeo, Andrew, et al.
Pubblicazione: (2025)
A Critical Evaluation of Defenses against Prompt Injection Attacks
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
di: Shi, Jiawen, et al.
Pubblicazione: (2024)
di: Shi, Jiawen, et al.
Pubblicazione: (2024)
Persistent Pre-Training Poisoning of LLMs
di: Zhang, Yiming, et al.
Pubblicazione: (2024)
di: Zhang, Yiming, et al.
Pubblicazione: (2024)
Stealthy and Persistent Unalignment on Large Language Models via Backdoor Injections
di: Cao, Yuanpu, et al.
Pubblicazione: (2023)
di: Cao, Yuanpu, et al.
Pubblicazione: (2023)
DataSentinel: A Game-Theoretic Detection of Prompt Injection Attacks
di: Liu, Yupei, et al.
Pubblicazione: (2025)
di: Liu, Yupei, et al.
Pubblicazione: (2025)
On Jailbreaking Quantized Language Models Through Fault Injection Attacks
di: Zahran, Noureldin, et al.
Pubblicazione: (2025)
di: Zahran, Noureldin, et al.
Pubblicazione: (2025)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
di: Xiang, Chong, et al.
Pubblicazione: (2026)
di: Xiang, Chong, et al.
Pubblicazione: (2026)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
di: Zou, Wei, et al.
Pubblicazione: (2026)
di: Zou, Wei, et al.
Pubblicazione: (2026)
Automating Prompt Leakage Attacks on Large Language Models Using Agentic Approach
di: Sternak, Tvrtko, et al.
Pubblicazione: (2025)
di: Sternak, Tvrtko, et al.
Pubblicazione: (2025)
PromptArmor: Simple yet Effective Prompt Injection Defenses
di: Shi, Tianneng, et al.
Pubblicazione: (2025)
di: Shi, Tianneng, et al.
Pubblicazione: (2025)
StruPhantom: Evolutionary Injection Attacks on Black-Box Tabular Agents Powered by Large Language Models
di: Feng, Yang, et al.
Pubblicazione: (2025)
di: Feng, Yang, et al.
Pubblicazione: (2025)
ShadowCode: Towards (Automatic) External Prompt Injection Attack against Code LLMs
di: Yang, Yuchen, et al.
Pubblicazione: (2024)
di: Yang, Yuchen, et al.
Pubblicazione: (2024)
Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection
di: Chen, Meng, et al.
Pubblicazione: (2026)
di: Chen, Meng, et al.
Pubblicazione: (2026)
AgentTypo: Adaptive Typographic Prompt Injection Attacks against Black-box Multimodal Agents
di: Li, Yanjie, et al.
Pubblicazione: (2025)
di: Li, Yanjie, et al.
Pubblicazione: (2025)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
di: Suo, Xuchen
Pubblicazione: (2024)
di: Suo, Xuchen
Pubblicazione: (2024)
One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
di: Chang, Zhiyuan, et al.
Pubblicazione: (2025)
di: Chang, Zhiyuan, et al.
Pubblicazione: (2025)
Review-Incorporated Model-Agnostic Profile Injection Attacks on Recommender Systems
di: Yang, Shiyi, et al.
Pubblicazione: (2024)
di: Yang, Shiyi, et al.
Pubblicazione: (2024)
Involuntary Jailbreak: On Self-Prompting Attacks
di: Guo, Yangyang, et al.
Pubblicazione: (2025)
di: Guo, Yangyang, et al.
Pubblicazione: (2025)
Casper: Prompt Sanitization for Protecting User Privacy in Web-Based Large Language Models
di: Chong, Chun Jie, et al.
Pubblicazione: (2024)
di: Chong, Chun Jie, et al.
Pubblicazione: (2024)
Defending Against Beta Poisoning Attacks in Machine Learning Models
di: Gulciftci, Nilufer, et al.
Pubblicazione: (2025)
di: Gulciftci, Nilufer, et al.
Pubblicazione: (2025)
Documenti analoghi
-
PIDP-Attack: Combining Prompt Injection with Database Poisoning Attacks on Retrieval-Augmented Generation Systems
di: Wang, Haozhen, et al.
Pubblicazione: (2026) -
Prompt Injection Attacks on Large Language Models in Oncology
di: Clusmann, Jan, et al.
Pubblicazione: (2024) -
Goal-guided Generative Prompt Injection Attack on Large Language Models
di: Zhang, Chong, et al.
Pubblicazione: (2024) -
Evaluation of Prompt Injection Defenses in Large Language Models
di: Deep, Priyal, et al.
Pubblicazione: (2026) -
PromptLocate: Localizing Prompt Injection Attacks
di: Jia, Yuqi, et al.
Pubblicazione: (2025)