May 2023ReviewedOpen access
Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Mario Fritz
AISec 2023
Abstract
Introduces indirect prompt injection attacks against LLM-integrated applications, demonstrating how adversaries can remotely control LLMs by injecting prompts into data sources the LLM retrieves.
Categories
#indirect-injection#rag#application-security
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Cite
@article{greshake2023not,
title = {{Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection}},
author = {Kai Greshake and Sahar Abdelnabi and Shailesh Mishra and Christoph Endres and Thorsten Holz and Mario Fritz},
year = {2023},
month = may,
journal = {AISec 2023},
eprint = {2302.12173},
archivePrefix = {arXiv},
doi = {10.1145/3605764.3623985},
url = {https://arxiv.org/abs/2302.12173}
}