Skip to content
Search
paperMay 2026Unreviewed

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments

Hongjang Yang, Hyunsik Na, Daeseon Choi

Abstract

LLM-based chatbot agents increasingly process user requests by combining natural-language reasoning with external tools such as web browsing. These capabilities improve usability, but they also create attack surfaces when untrusted external content is processed as part of a user' s task. This paper studies a privacy-leakage attack chain based on indirect prompt injection in black-box chatbot environments, where the attacker has no access to model weights, system prompts, or agent implementation

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM02Sensitive Information Disclosure
MITRE ATLAS
  • AML.T0024.000Infer Training Data Membership
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{yang2026empirical,
  title = {{An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments}},
  author = {Hongjang Yang and Hyunsik Na and Daeseon Choi},
  year = {2026},
  month = may,
  eprint = {2605.18133},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.18133}
}