June 2025Unreviewed
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
Zhilong Wang, N. Nagaraja, Lan Zhang, Hayretdin Bahşi, Pawan Patil, Peng Liu
2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S)
Abstract
LLM agents are widely used as agents for customer support, content generation, and code assistance. However, they are vulnerable to prompt injection attacks, where adversarial inputs manipulate the model’s behavior. Traditional defenses like input sanitization, guard models, and guardrails are either cumbersome or ineffective. In this paper, we propose a novel, lightweight defense mechanism called Polymorphic Prompt Assembling (PPA), which protects against prompt injection with near-zero overhea
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@inproceedings{wang2025protect,
title = {{To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt}},
author = {Zhilong Wang and N. Nagaraja and Lan Zhang and Hayretdin Bahşi and Pawan Patil and Peng Liu},
year = {2025},
month = jun,
booktitle = {2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S)},
eprint = {2506.05739},
archivePrefix = {arXiv},
doi = {10.1109/DSN-S65789.2025.00037},
url = {https://www.semanticscholar.org/paper/020ad9b3a8022ac6464cc06b2e80c2a267001e77}
}