April 2026Unreviewed
Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives
Soheil Khodayari, Xuenan Zhang, Bhupendra Acharya, Giancarlo Pellegrino
Abstract
As LLMs are increasingly integrated into systems that browse, retrieve, summarize, and act on web content, webpages have become an untrusted input vector for downstream model behavior. This enables site owners, contributors, and adversaries to embed instructions directly in web resources, i.e., indirect prompt injections. While prior work demonstrates such attacks in controlled settings, their prevalence, deployment, and real-world impact remain unclear. We present one of the first large-scale e
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{khodayari2026indirect,
title = {{Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives}},
author = {Soheil Khodayari and Xuenan Zhang and Bhupendra Acharya and Giancarlo Pellegrino},
year = {2026},
month = apr,
eprint = {2604.27202},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.27202}
}