November 2025Unreviewed
Taxonomy, Evaluation and Exploitation of IPI-Centric LLM Agent Defense Frameworks
Zimo Ji, Xunguang Wang, Zongjie Li, Pingchuan Ma, Yudong Gao, Daoyuan Wu, Xincheng Yan, Tian Tian, Shuai Wang
arXiv.org
Abstract
Large Language Model (LLM)-based agents with function-calling capabilities are increasingly deployed, but remain vulnerable to Indirect Prompt Injection (IPI) attacks that hijack their tool calls. In response, numerous IPI-centric defense frameworks have emerged. However, these defenses are fragmented, lacking a unified taxonomy and comprehensive evaluation. In this Systematization of Knowledge (SoK), we present the first comprehensive analysis of IPI-centric defense frameworks. We introduce a c
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{ji2025taxonomy,
title = {{Taxonomy, Evaluation and Exploitation of IPI-Centric LLM Agent Defense Frameworks}},
author = {Zimo Ji and Xunguang Wang and Zongjie Li and Pingchuan Ma and Yudong Gao and Daoyuan Wu and Xincheng Yan and Tian Tian and Shuai Wang},
year = {2025},
month = nov,
eprint = {2511.15203},
archivePrefix = {arXiv},
doi = {10.48550/arXiv.2511.15203},
url = {https://www.semanticscholar.org/paper/66c8e83ed0fc215dc8be0e44715a692ef27f005b}
}