EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Reddy, Pavan, Gujral, Aditya Sanjay |
|---|---|
| Format: | Preprint |
| Publié: |
2025
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
Silent Egress: When Implicit Prompt Injection Makes LLM Agents Leak Without a Trace
par: Lan, Qianlong, et autres
Publié: (2026)
par: Lan, Qianlong, et autres
Publié: (2026)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
par: Ferrag, Mohamed Amine, et autres
Publié: (2025)
par: Ferrag, Mohamed Amine, et autres
Publié: (2025)
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
par: Chang, Hongyan, et autres
Publié: (2026)
par: Chang, Hongyan, et autres
Publié: (2026)
In-Browser LLM-Guided Fuzzing for Real-Time Prompt Injection Testing in Agentic AI Browsers
par: Cohen, Avihay
Publié: (2025)
par: Cohen, Avihay
Publié: (2025)
LeakSealer: A Semisupervised Defense for LLMs Against Prompt Injection and Leakage Attacks
par: Panebianco, Francesco, et autres
Publié: (2025)
par: Panebianco, Francesco, et autres
Publié: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
par: Wang, Zhilong, et autres
Publié: (2025)
par: Wang, Zhilong, et autres
Publié: (2025)
OptiLeak: Efficient Prompt Reconstruction via Reinforcement Learning in Multi-tenant LLM Services
par: Wang, Longxiang, et autres
Publié: (2026)
par: Wang, Longxiang, et autres
Publié: (2026)
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
par: Shi, Jiawen, et autres
Publié: (2024)
par: Shi, Jiawen, et autres
Publié: (2024)
Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
par: Lee, Donghyun, et autres
Publié: (2024)
par: Lee, Donghyun, et autres
Publié: (2024)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
par: Xiang, Chong, et autres
Publié: (2026)
par: Xiang, Chong, et autres
Publié: (2026)
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
par: Zhang, Mohan, et autres
Publié: (2026)
par: Zhang, Mohan, et autres
Publié: (2026)
Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior
par: Lian, Zhuotao, et autres
Publié: (2025)
par: Lian, Zhuotao, et autres
Publié: (2025)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
par: Zhong, Peter Yong, et autres
Publié: (2025)
par: Zhong, Peter Yong, et autres
Publié: (2025)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
par: Suo, Xuchen
Publié: (2024)
par: Suo, Xuchen
Publié: (2024)
Bypassing Prompt Injection Detectors through Evasive Injections
par: Rahman, Md Jahedur, et autres
Publié: (2026)
par: Rahman, Md Jahedur, et autres
Publié: (2026)
PromptLocate: Localizing Prompt Injection Attacks
par: Jia, Yuqi, et autres
Publié: (2025)
par: Jia, Yuqi, et autres
Publié: (2025)
How Not to Detect Prompt Injections with an LLM
par: Choudhary, Sarthak, et autres
Publié: (2025)
par: Choudhary, Sarthak, et autres
Publié: (2025)
CompressionAttack: Exploiting Prompt Compression as a New Attack Surface in LLM-Powered Agents
par: Liu, Zesen, et autres
Publié: (2025)
par: Liu, Zesen, et autres
Publié: (2025)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
par: Sehwag, Udari Madhushani, et autres
Publié: (2026)
par: Sehwag, Udari Madhushani, et autres
Publié: (2026)
Defeating Prompt Injections by Design
par: Debenedetti, Edoardo, et autres
Publié: (2025)
par: Debenedetti, Edoardo, et autres
Publié: (2025)
MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs
par: Ding, Ruyi, et autres
Publié: (2025)
par: Ding, Ruyi, et autres
Publié: (2025)
Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks
par: Pasquini, Dario, et autres
Publié: (2024)
par: Pasquini, Dario, et autres
Publié: (2024)
The Echo Chamber Multi-Turn LLM Jailbreak
par: Alobaid, Ahmad, et autres
Publié: (2026)
par: Alobaid, Ahmad, et autres
Publié: (2026)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
par: Chen, Sizhe, et autres
Publié: (2025)
par: Chen, Sizhe, et autres
Publié: (2025)
PromptArmor: Simple yet Effective Prompt Injection Defenses
par: Shi, Tianneng, et autres
Publié: (2025)
par: Shi, Tianneng, et autres
Publié: (2025)
Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
par: Johnson, Sam, et autres
Publié: (2025)
par: Johnson, Sam, et autres
Publié: (2025)
A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems
par: Wu, Fangzhou, et autres
Publié: (2024)
par: Wu, Fangzhou, et autres
Publié: (2024)
Token-Efficient Prompt Injection Attack: Provoking Cessation in LLM Reasoning via Adaptive Token Compression
par: Cui, Yu, et autres
Publié: (2025)
par: Cui, Yu, et autres
Publié: (2025)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
par: Wang, Zhun, et autres
Publié: (2025)
par: Wang, Zhun, et autres
Publié: (2025)
System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
par: Li, Zongze, et autres
Publié: (2025)
par: Li, Zongze, et autres
Publié: (2025)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
par: Zhao, Wei, et autres
Publié: (2026)
par: Zhao, Wei, et autres
Publié: (2026)
Prompt Injection 2.0: Hybrid AI Threats
par: McHugh, Jeremy, et autres
Publié: (2025)
par: McHugh, Jeremy, et autres
Publié: (2025)
Securing AI Agents Against Prompt Injection Attacks
par: Ramakrishnan, Badrinath, et autres
Publié: (2025)
par: Ramakrishnan, Badrinath, et autres
Publié: (2025)
Defending against Indirect Prompt Injection by Instruction Detection
par: Wen, Tongyu, et autres
Publié: (2025)
par: Wen, Tongyu, et autres
Publié: (2025)
Analysis of LLMs Against Prompt Injection and Jailbreak Attacks
par: Jaiswal, Piyush, et autres
Publié: (2026)
par: Jaiswal, Piyush, et autres
Publié: (2026)
Evaluation of Prompt Injection Defenses in Large Language Models
par: Deep, Priyal, et autres
Publié: (2026)
par: Deep, Priyal, et autres
Publié: (2026)
Assessing Prompt Injection Risks in 200+ Custom GPTs
par: Yu, Jiahao, et autres
Publié: (2023)
par: Yu, Jiahao, et autres
Publié: (2023)
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems
par: Turgut, İpek Abasıkeleş, et autres
Publié: (2026)
par: Turgut, İpek Abasıkeleş, et autres
Publié: (2026)
PIDP-Attack: Combining Prompt Injection with Database Poisoning Attacks on Retrieval-Augmented Generation Systems
par: Wang, Haozhen, et autres
Publié: (2026)
par: Wang, Haozhen, et autres
Publié: (2026)
Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
par: Maloyan, Narek, et autres
Publié: (2026)
par: Maloyan, Narek, et autres
Publié: (2026)
Documents similaires
-
Silent Egress: When Implicit Prompt Injection Makes LLM Agents Leak Without a Trace
par: Lan, Qianlong, et autres
Publié: (2026) -
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
par: Ferrag, Mohamed Amine, et autres
Publié: (2025) -
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
par: Chang, Hongyan, et autres
Publié: (2026) -
In-Browser LLM-Guided Fuzzing for Real-Time Prompt Injection Testing in Agentic AI Browsers
par: Cohen, Avihay
Publié: (2025) -
LeakSealer: A Semisupervised Defense for LLMs Against Prompt Injection and Leakage Attacks
par: Panebianco, Francesco, et autres
Publié: (2025)