August 2026Unreviewed
The Anatomy of a Prompt Injection: A Component Model for Structured Analysis
Jeremy McHugh
Abstract
Four years after prompt injection was first identified in 2022, attacks are still predominantly documented as verbatim strings rather than structured exploits, despite advancing agent capabilities and threat actors embedding injections to subvert AI-assisted security analysis. This paper formalizes the structure of prompt-injection artifacts, enabling defenders, red teamers, and cyber threat intelligence (CTI) teams to label, compare, and mutate attacks without relying on fragile string matching
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
NIST AI Risk Management Framework
- MEASUREMeasure
Suggested from the entry's categories.
Cite
@misc{mchugh2026anatomy,
title = {{The Anatomy of a Prompt Injection: A Component Model for Structured Analysis}},
author = {Jeremy McHugh},
year = {2026},
month = aug,
eprint = {2608.07808},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.07808}
}