Skip to content
Search
paperMay 2023ReviewedOpen access

Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Mario Fritz

AISec 2023

Abstract

Introduces indirect prompt injection attacks against LLM-integrated applications, demonstrating how adversaries can remotely control LLMs by injecting prompts into data sources the LLM retrieves.

Categories

#indirect-injection#rag#application-security

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Cite

@article{greshake2023not,
  title = {{Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection}},
  author = {Kai Greshake and Sahar Abdelnabi and Shailesh Mishra and Christoph Endres and Thorsten Holz and Mario Fritz},
  year = {2023},
  month = may,
  journal = {AISec 2023},
  eprint = {2302.12173},
  archivePrefix = {arXiv},
  doi = {10.1145/3605764.3623985},
  url = {https://arxiv.org/abs/2302.12173}
}