Skip to content
Search
paperNovember 2025Unreviewed

Taxonomy, Evaluation and Exploitation of IPI-Centric LLM Agent Defense Frameworks

Zimo Ji, Xunguang Wang, Zongjie Li, Pingchuan Ma, Yudong Gao, Daoyuan Wu, Xincheng Yan, Tian Tian, Shuai Wang

arXiv.org

Abstract

Large Language Model (LLM)-based agents with function-calling capabilities are increasingly deployed, but remain vulnerable to Indirect Prompt Injection (IPI) attacks that hijack their tool calls. In response, numerous IPI-centric defense frameworks have emerged. However, these defenses are fragmented, lacking a unified taxonomy and comprehensive evaluation. In this Systematization of Knowledge (SoK), we present the first comprehensive analysis of IPI-centric defense frameworks. We introduce a c

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{ji2025taxonomy,
  title = {{Taxonomy, Evaluation and Exploitation of IPI-Centric LLM Agent Defense Frameworks}},
  author = {Zimo Ji and Xunguang Wang and Zongjie Li and Pingchuan Ma and Yudong Gao and Daoyuan Wu and Xincheng Yan and Tian Tian and Shuai Wang},
  year = {2025},
  month = nov,
  eprint = {2511.15203},
  archivePrefix = {arXiv},
  doi = {10.48550/arXiv.2511.15203},
  url = {https://www.semanticscholar.org/paper/66c8e83ed0fc215dc8be0e44715a692ef27f005b}
}