May 2026Unreviewed
An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments
Hongjang Yang, Hyunsik Na, Daeseon Choi
Abstract
LLM-based chatbot agents increasingly process user requests by combining natural-language reasoning with external tools such as web browsing. These capabilities improve usability, but they also create attack surfaces when untrusted external content is processed as part of a user' s task. This paper studies a privacy-leakage attack chain based on indirect prompt injection in black-box chatbot environments, where the attacker has no access to model weights, system prompts, or agent implementation
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
MITRE ATLAS
- AML.T0024.000Infer Training Data Membership
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{yang2026empirical,
title = {{An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments}},
author = {Hongjang Yang and Hyunsik Na and Daeseon Choi},
year = {2026},
month = may,
eprint = {2605.18133},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.18133}
}