When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Motlagh, Farzad Nourmohammadzadeh, Hajizadeh, Mehrdad, Majd, Mehryar, Najafi, Pejman, Cheng, Feng, Meinel, Christoph
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914552287854592
author Motlagh, Farzad Nourmohammadzadeh
Hajizadeh, Mehrdad
Majd, Mehryar
Najafi, Pejman
Cheng, Feng
Meinel, Christoph
author_facet Motlagh, Farzad Nourmohammadzadeh
Hajizadeh, Mehrdad
Majd, Mehryar
Najafi, Pejman
Cheng, Feng
Meinel, Christoph
contents Natural language interfaces to structured databases are becoming increasingly common, largely due to advances in large language models (LLMs) that enable users to query data using conversational input rather than formal query languages such as SQL. While this paradigm significantly improves usability and accessibility, it introduces new security risks, particularly the amplification of SQL injection vulnerabilities through the prompt-to-SQL translation process. Malicious users can exploit these mechanisms by crafting adversarial prompts that manipulate model behavior and generate unsafe queries. In this work, we propose a multi-layered security framework designed to detect and mitigate LLM-mediated SQL injection attacks. The framework integrates a front-end security shield for prompt sanitization, an advanced threat detection model for behavioral and semantic anomaly identification, and a signature-based control layer for known attack patterns. We evaluate the proposed framework under diverse and realistic attack scenarios, including prompt injection, obfuscated SQL payloads, and context-manipulation attacks. To ensure robustness, we generate and curate a comprehensive benchmark dataset of adversarial prompts and assess performance across a fine-tuned LLM configuration. Experimental results demonstrate that the proposed approach achieves high detection accuracy while maintaining low false-positive rates, significantly improving the secure deployment of LLM-powered database applications.
format Preprint
id arxiv_https___arxiv_org_abs_2605_10176
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications
Motlagh, Farzad Nourmohammadzadeh
Hajizadeh, Mehrdad
Majd, Mehryar
Najafi, Pejman
Cheng, Feng
Meinel, Christoph
Cryptography and Security
Artificial Intelligence
D.4.6; H.2; I.2
Natural language interfaces to structured databases are becoming increasingly common, largely due to advances in large language models (LLMs) that enable users to query data using conversational input rather than formal query languages such as SQL. While this paradigm significantly improves usability and accessibility, it introduces new security risks, particularly the amplification of SQL injection vulnerabilities through the prompt-to-SQL translation process. Malicious users can exploit these mechanisms by crafting adversarial prompts that manipulate model behavior and generate unsafe queries. In this work, we propose a multi-layered security framework designed to detect and mitigate LLM-mediated SQL injection attacks. The framework integrates a front-end security shield for prompt sanitization, an advanced threat detection model for behavioral and semantic anomaly identification, and a signature-based control layer for known attack patterns. We evaluate the proposed framework under diverse and realistic attack scenarios, including prompt injection, obfuscated SQL payloads, and context-manipulation attacks. To ensure robustness, we generate and curate a comprehensive benchmark dataset of adversarial prompts and assess performance across a fine-tuned LLM configuration. Experimental results demonstrate that the proposed approach achieves high detection accuracy while maintaining low false-positive rates, significantly improving the secure deployment of LLM-powered database applications.
title When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications
topic Cryptography and Security
Artificial Intelligence
D.4.6; H.2; I.2
url https://arxiv.org/abs/2605.10176