Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
Fuente:
arXiv
Salvato in:
| Autori principali: | Chang, Hongyan, Bao, Ergute, Luo, Xinjian, Yu, Ting |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Defending against Indirect Prompt Injection by Instruction Detection
di: Wen, Tongyu, et al.
Pubblicazione: (2025)
di: Wen, Tongyu, et al.
Pubblicazione: (2025)
QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
di: Xie, Yuchong, et al.
Pubblicazione: (2025)
di: Xie, Yuchong, et al.
Pubblicazione: (2025)
Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
di: Johnson, Sam, et al.
Pubblicazione: (2025)
di: Johnson, Sam, et al.
Pubblicazione: (2025)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
di: Wang, Zhun, et al.
Pubblicazione: (2025)
di: Wang, Zhun, et al.
Pubblicazione: (2025)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
di: Zhao, Wei, et al.
Pubblicazione: (2026)
di: Zhao, Wei, et al.
Pubblicazione: (2026)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
di: Xiang, Chong, et al.
Pubblicazione: (2026)
di: Xiang, Chong, et al.
Pubblicazione: (2026)
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection
di: Zhao, Lei, et al.
Pubblicazione: (2026)
di: Zhao, Lei, et al.
Pubblicazione: (2026)
ICON: Indirect Prompt Injection Defense for Agents based on Inference-Time Correction
di: Wang, Che, et al.
Pubblicazione: (2026)
di: Wang, Che, et al.
Pubblicazione: (2026)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
di: Zhu, Kaijie, et al.
Pubblicazione: (2025)
di: Zhu, Kaijie, et al.
Pubblicazione: (2025)
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
di: Wang, Che, et al.
Pubblicazione: (2026)
di: Wang, Che, et al.
Pubblicazione: (2026)
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks
di: Syros, Georgios, et al.
Pubblicazione: (2026)
di: Syros, Georgios, et al.
Pubblicazione: (2026)
When Reject Turns into Accept: Quantifying the Vulnerability of LLM-Based Scientific Reviewers to Indirect Prompt Injection
di: Sahoo, Devanshu, et al.
Pubblicazione: (2025)
di: Sahoo, Devanshu, et al.
Pubblicazione: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
di: Chia-Pei, et al.
Pubblicazione: (2026)
di: Chia-Pei, et al.
Pubblicazione: (2026)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
di: Dziemian, Mateusz, et al.
Pubblicazione: (2026)
di: Dziemian, Mateusz, et al.
Pubblicazione: (2026)
PIDP-Attack: Combining Prompt Injection with Database Poisoning Attacks on Retrieval-Augmented Generation Systems
di: Wang, Haozhen, et al.
Pubblicazione: (2026)
di: Wang, Haozhen, et al.
Pubblicazione: (2026)
Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
di: Lee, Donghyun, et al.
Pubblicazione: (2024)
di: Lee, Donghyun, et al.
Pubblicazione: (2024)
IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents
di: An, Hengyu, et al.
Pubblicazione: (2025)
di: An, Hengyu, et al.
Pubblicazione: (2025)
Trojan Horses in Recruiting: A Red-Teaming Case Study on Indirect Prompt Injection in Standard vs. Reasoning Models
di: Wirth, Manuel
Pubblicazione: (2026)
di: Wirth, Manuel
Pubblicazione: (2026)
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
di: Shi, Jiawen, et al.
Pubblicazione: (2024)
di: Shi, Jiawen, et al.
Pubblicazione: (2024)
The Cognitive Firewall:Securing Browser Based AI Agents Against Indirect Prompt Injection Via Hybrid Edge Cloud Defense
di: Lan, Qianlong, et al.
Pubblicazione: (2026)
di: Lan, Qianlong, et al.
Pubblicazione: (2026)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
di: Zhong, Peter Yong, et al.
Pubblicazione: (2025)
di: Zhong, Peter Yong, et al.
Pubblicazione: (2025)
Token-Efficient Prompt Injection Attack: Provoking Cessation in LLM Reasoning via Adaptive Token Compression
di: Cui, Yu, et al.
Pubblicazione: (2025)
di: Cui, Yu, et al.
Pubblicazione: (2025)
Rag and Roll: An End-to-End Evaluation of Indirect Prompt Manipulations in LLM-based Application Frameworks
di: De Stefano, Gianluca, et al.
Pubblicazione: (2024)
di: De Stefano, Gianluca, et al.
Pubblicazione: (2024)
The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
di: Jia, Feiran, et al.
Pubblicazione: (2024)
di: Jia, Feiran, et al.
Pubblicazione: (2024)
Signed-Prompt: A New Approach to Prevent Prompt Injection Attacks Against LLM-Integrated Applications
di: Suo, Xuchen
Pubblicazione: (2024)
di: Suo, Xuchen
Pubblicazione: (2024)
Bypassing Prompt Injection Detectors through Evasive Injections
di: Rahman, Md Jahedur, et al.
Pubblicazione: (2026)
di: Rahman, Md Jahedur, et al.
Pubblicazione: (2026)
EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System
di: Reddy, Pavan, et al.
Pubblicazione: (2025)
di: Reddy, Pavan, et al.
Pubblicazione: (2025)
PromptLocate: Localizing Prompt Injection Attacks
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
di: Jia, Yuqi, et al.
Pubblicazione: (2025)
How Not to Detect Prompt Injections with an LLM
di: Choudhary, Sarthak, et al.
Pubblicazione: (2025)
di: Choudhary, Sarthak, et al.
Pubblicazione: (2025)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
di: Sehwag, Udari Madhushani, et al.
Pubblicazione: (2026)
di: Sehwag, Udari Madhushani, et al.
Pubblicazione: (2026)
SD-RAG: A Prompt-Injection-Resilient Framework for Selective Disclosure in Retrieval-Augmented Generation
di: Masoud, Aiman Al, et al.
Pubblicazione: (2026)
di: Masoud, Aiman Al, et al.
Pubblicazione: (2026)
Defeating Prompt Injections by Design
di: Debenedetti, Edoardo, et al.
Pubblicazione: (2025)
di: Debenedetti, Edoardo, et al.
Pubblicazione: (2025)
Meta SecAlign: A Secure Foundation LLM Against Prompt Injection Attacks
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
di: Chen, Sizhe, et al.
Pubblicazione: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
di: Ferrag, Mohamed Amine, et al.
Pubblicazione: (2025)
di: Ferrag, Mohamed Amine, et al.
Pubblicazione: (2025)
Assessing Prompt Injection Risks in 200+ Custom GPTs
di: Yu, Jiahao, et al.
Pubblicazione: (2023)
di: Yu, Jiahao, et al.
Pubblicazione: (2023)
PromptArmor: Simple yet Effective Prompt Injection Defenses
di: Shi, Tianneng, et al.
Pubblicazione: (2025)
di: Shi, Tianneng, et al.
Pubblicazione: (2025)
Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks
di: Pasquini, Dario, et al.
Pubblicazione: (2024)
di: Pasquini, Dario, et al.
Pubblicazione: (2024)
In-Browser LLM-Guided Fuzzing for Real-Time Prompt Injection Testing in Agentic AI Browsers
di: Cohen, Avihay
Pubblicazione: (2025)
di: Cohen, Avihay
Pubblicazione: (2025)
Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives
di: Khodayari, Soheil, et al.
Pubblicazione: (2026)
di: Khodayari, Soheil, et al.
Pubblicazione: (2026)
Documenti analoghi
-
Defending against Indirect Prompt Injection by Instruction Detection
di: Wen, Tongyu, et al.
Pubblicazione: (2025) -
QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
di: Xie, Yuchong, et al.
Pubblicazione: (2025) -
Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
di: Johnson, Sam, et al.
Pubblicazione: (2025) -
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
di: Wang, Zhun, et al.
Pubblicazione: (2025) -
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
di: Zhao, Wei, et al.
Pubblicazione: (2026)