Skip to content

Prompt Injection

Direct, indirect, and multi-turn prompt injection attacks

Resources
278
Page
5/6

Newest first

Search instead
paper2026International Journal of Information SecurityUnreviewed

Hive-AI: a defended multi-service honeypot framework for generative AI APIs

Sebastián Vargas Yáñez, Sergio Tobón

Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today…

Prompt InjectionOpen access
paper2026Yalvaç akademi dergisiUnreviewed

Leakage-Aware Cross-Dataset Evaluation of Prompt Injection Detection Using Classical Machine Learning and Transformer Models

Oğuzhan Kilim

The widespread adoption of systems based on Large Language Models has made the reliable detection of prompt injection attacks a critical requirement. However, high performance achieved on training and test splits generated from the same data source does not guarantee that models…

paper2026Security and PrivacyUnreviewed

PERSIST : Threat Modeling Memory‐Persistent AI Agents in Cloud‐to‐Edge Environments

Albert Adusei Brobbey, Narayan P. Bhosale

Agentic artificial intelligence systems increasingly depend on persistent runtime memory, including vector databases, episodic memory stores, long‐term retrieval indices, and cloud‐to‐edge replicas. Existing security frameworks address prompt injection, data poisoning, and…

paper2026IEEE Transactions on Dependable and Secure ComputingUnreviewed

Efficient Prompt Security Detection for LLM Service Deployment in Edge-Cloud Networks

Wen-Jing Chen, Jie Cui, Wenjie Huang +3

While Large Language Models (LLMs) have achieved revolutionary advancements in natural language processing, their inherent vulnerability to prompt injection attacks has raised significant security concerns. Existing security detection approaches for LLM deployment often fail to…

paper2026ComputersUnreviewed

Evaluating Indirect Prompt Injection Defenses in Tool-Using LLM Agents: Security, Utility, and Replication

Adil Khan, Khaled AlKhanbashi, Azza Mohamed

Large language model (LLM) agents that retrieve external content and use tools are vulnerable to indirect prompt injection, in which untrusted content contains instructions intended to influence agent behavior. We evaluated four defenses and an undefended control across GPT-5.4,…

paper2026ElectronicsUnreviewed

Securing the Prompt Pipeline: A Systematic Review of Defense Mechanisms Against Prompt-Based Attacks in LLM Agents

Sana Mourad, E. E. Abdallah, Mohammad Ababneh

Current language model deployments face growing security challenges from prompt-based attacks, including jailbreaks, direct and indirect prompt injection, and instruction hijacking, which often evade traditional rule-based safeguards. As these models are increasingly integrated…

paper2026Unreviewed

Security of Foundation-Model-Powered Embodied Agents: Attack Surfaces, Attacks, Defenses, and Evaluation

Jiawei Liu, Jiacheng Guo, Tian Zhang +4

Foundation models are increasingly used for perception, reasoning, planning, and action generation in embodied agents, creating security risks that can propagate from digital inputs to physical behavior. Existing surveys often organize threats by mechanisms such as jailbreaks,…

paper2026ElectronicsUnreviewed

DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection

Alaa Alnemari, Mashael M. Alsulami

Large Language Models (LLMs) are increasingly deployed in security-critical applications but remain vulnerable to indirect prompt injection attacks that cannot be fully addressed by conventional prompt detection techniques. This paper proposes DT-GenShield, a Digital Twin-driven…

Prompt InjectionOpen access
paper2026ElectronicsUnreviewed

A Privacy-Preserving Middleware Architecture for Detecting Prompt Injection and Sensitive Data Exposure in Large-Language-Model Interactions

Adam Ait Hsine, A. Arabo

The deployment of large language models (LLMs) in real-world applications introduces a compounding security problem: detecting adversarial inputs such as prompt injection and jailbreak-driven data leakage while simultaneously preventing the detection mechanism itself from…

paper2026Al-Noor Journal of Engineering Management and Computer ScienceUnreviewed

Real-Time Detection and Mitigation of Prompt Injection Attacks in LLM-Integrated Enterprise Systems

Fatimah Alhamzawi

Large language models (LLMs) embedded in enterprise workflows cannot structurally distinguish legitimate instructions from adversarial ones in the same token stream, making prompt injection OWASP's top LLM risk for two consecutive editions a persistent threat across direct and…

Prompt InjectionOpen access
paper2026Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2Unreviewed

The 2nd SeT-LLM Workshop on Secure and Trustworthy Large Language Models

Lu Lin, Jinghui Chen, Ting Wang +4

Large language models (LLMs) are increasingly embedded as core components of data-centric systems, supporting analytical decision making, and automated reasoning over large-scale, heterogeneous datasets. Yet their deployment in open-world environments raises fundamental…

paper2026Applied SciencesUnreviewed

Design of a Security Framework for Multi-Agent Systems Based on Model Context Protocol in SOC Environments

Rodrigo Tavares de Pina Simões, Xavier Larriva-Novo, Carmen Sánchez-Zas +2

Security Operations Centers (SOCs) rely on Level 1 analysts to triage increasing alert volumes amid alert fatigue and tool fragmentation. LLM-based multi-agent systems using the Model Context Protocol (MCP) are being adopted to automate these tasks, but their autonomy and tool…

paper2026Scientific Journal of Computer ScienceUnreviewed

D2ANN-RL: Defense-in-Depth ANN-Reinforcement Learning Framework for LLM Chatbot Code Injection Mitigation

Victor Omoboye Oluwasegun, O. Falebita, N. Adebola +6

The growing cybersecurity vulnerabilities in artificial intelligence (AI) service models, particularly Large Language Models (LLMs), highlight code injection as a critical threat to chatbot reliability and safe deployment. On the account that LLMs process inputs as…

Prompt InjectionOpen access
paper20262026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS)Unreviewed

Evaluating Prompt Injection Risk and Guardrails in LLM-Enabled Home IoT Assistants

Shazid Bin Zaman, Sohan Gyawali, C. Popoviciu +2

Smart home virtual assistants are increasingly powered by large language models to enable information retrieval and home device actuation. As a result, intelligent home environments are becoming more exposed to untrusted inputs, increasing their susceptibility to prompt…

paper2026The Scholar Journal for Sciences & TechnologyUnreviewed

Security Risk Assessment and Layered Protection Strategies for Large Language Model Banking Chatbots with Privacy Considerations

Galal Eltayeb, Abdalilah Alhalangy

Abstract But now, given the AI revolution and increased interest in bringing virtual agents and assistants to life banks too are testing LLM-powered AI agents that may assist customers, explain and customize products as well as simplify operational work done by bank employees in…

paper2026Unreviewed

LLM-powered SOC Assistants: Prompt Injection Risks in Threat Triage

Tayyeb Nadeem Somro, Bilal Arshad, Ammara Gul

Security Operations Centres (SOCs) are increasingly deploying Large Language Model (LLM) assistants to accelerate threat triage, alert prioritisation, and incident response. While these systems offer substantial productivity gains, their integration into security-critical…

paper2026International Journal of Advanced Artificial Intelligence ResearchUnreviewed

Formal Operational Models for Protecting Web Interfaces of Legal LLM Systems from Prompt Injection and Insecure Output Handling

Grigorii Danileiko

The proliferation of large language model (LLM) systems in legal technology platforms has created a new class of web-interface security vulnerabilities that existing application security frameworks address incompletely. This paper examines prompt injection and insecure output…

paper2026Unreviewed

Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis

Divya Pandey, Shivani Manchanda, Gangesh Pathak +1

Clinical large language model (LLM) agents are entering production hospital deployments, where they read longitudinal electronic health records (EHRs), retrieve evidence from clinical knowledge bases, and assist with summarization, dosing, triage, and guideline-based decisions.…

paper2026Stout in Computer Science and Technology StudiesUnreviewed

Continual Red-Teaming and Guardrail Distillation for Tool-Using LLM Agents: Prompt-Injection Resistance with Utility Preservation

Wesley Gao

Tool-using language-model agents can convert indirect prompt injection into consequential actions, making guardrail quality a joint security, utility, and efficiency problem. This study evaluates a ReAct-style control, native tool filtering, deterministic self-verification, a…

paper2026Unreviewed

Securing LLM Powered AI Browsers Against Prompt Injection: A Comprehensive Survey, Threat Taxonomy, and Defense Framework

Sabin Adhikari, Roshan Paudel, Dipesh Gautam +4

Prompt injection is a serious threat to the security of large language models operating in AI-powered browsers and autonomous web agents, which depend on the ability of those models to interpret instructions correctly as they are used for automated browsing, data extraction or…

paper2026Unreviewed

Image-embedded prompt injection vulnerability of vision-language models in dental radiology: a cross-vendor attack–defense evaluation

Babak Saravi, Daman Deep Singh, Lara Schorn +4

Abstract Image-embedded prompt injection — adversarial text rendered into the pixel data of medical images — is an emerging threat to vision-language models (VLMs) used in clinical decision support. We systematically evaluated this vulnerability across four production-tier VLMs…

paper2025Conference on Empirical Methods in Natural Language ProcessingUnreviewed

IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents

Hengyu An, Jinghuai Zhang, Tianyu Du +4

Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks. However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool…

paper2025arXiv.orgUnreviewed

Red Teaming the Mind of the Machine: A Systematic Evaluation of Prompt Injection and Jailbreak Vulnerabilities in LLMs

Chetan Pathade

Large Language Models (LLMs) are increasingly integrated into consumer and enterprise applications. Despite their capabilities, they remain susceptible to adversarial attacks such as prompt injection and jailbreaks that override alignment safeguards. This paper provides a…