Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866908505217171456 |
|---|---|
| author | Lian, Zhuotao Wang, Weiyu Zeng, Qingkui Nakanishi, Toru Kitasuka, Teruaki Su, Chunhua |
| author_facet | Lian, Zhuotao Wang, Weiyu Zeng, Qingkui Nakanishi, Toru Kitasuka, Teruaki Su, Chunhua |
| contents | Large Language Models (LLMs) are widely deployed in applications that accept user-submitted content, such as uploaded documents or pasted text, for tasks like summarization and question answering. In this paper, we identify a new class of attacks, prompt in content injection, where adversarial instructions are embedded in seemingly benign inputs. When processed by the LLM, these hidden prompts can manipulate outputs without user awareness or system compromise, leading to biased summaries, fabricated claims, or misleading suggestions. We demonstrate the feasibility of such attacks across popular platforms, analyze their root causes including prompt concatenation and insufficient input isolation, and discuss mitigation strategies. Our findings reveal a subtle yet practical threat in real-world LLM workflows. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2508_19287 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior Lian, Zhuotao Wang, Weiyu Zeng, Qingkui Nakanishi, Toru Kitasuka, Teruaki Su, Chunhua Cryptography and Security Artificial Intelligence Large Language Models (LLMs) are widely deployed in applications that accept user-submitted content, such as uploaded documents or pasted text, for tasks like summarization and question answering. In this paper, we identify a new class of attacks, prompt in content injection, where adversarial instructions are embedded in seemingly benign inputs. When processed by the LLM, these hidden prompts can manipulate outputs without user awareness or system compromise, leading to biased summaries, fabricated claims, or misleading suggestions. We demonstrate the feasibility of such attacks across popular platforms, analyze their root causes including prompt concatenation and insufficient input isolation, and discuss mitigation strategies. Our findings reveal a subtle yet practical threat in real-world LLM workflows. |
| title | Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2508.19287 |