Skip to content
Search
paperJune 2025Unreviewed

To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt

Zhilong Wang, N. Nagaraja, Lan Zhang, Hayretdin Bahşi, Pawan Patil, Peng Liu

2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S)

Abstract

LLM agents are widely used as agents for customer support, content generation, and code assistance. However, they are vulnerable to prompt injection attacks, where adversarial inputs manipulate the model’s behavior. Traditional defenses like input sanitization, guard models, and guardrails are either cumbersome or ineffective. In this paper, we propose a novel, lightweight defense mechanism called Polymorphic Prompt Assembling (PPA), which protects against prompt injection with near-zero overhea

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@inproceedings{wang2025protect,
  title = {{To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt}},
  author = {Zhilong Wang and N. Nagaraja and Lan Zhang and Hayretdin Bahşi and Pawan Patil and Peng Liu},
  year = {2025},
  month = jun,
  booktitle = {2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S)},
  eprint = {2506.05739},
  archivePrefix = {arXiv},
  doi = {10.1109/DSN-S65789.2025.00037},
  url = {https://www.semanticscholar.org/paper/020ad9b3a8022ac6464cc06b2e80c2a267001e77}
}