Skip to content
Search
paperSeptember 2026Unreviewed

Indirect Prompt Injection in Municipal Document-Processing Copilots: Attacks, Defences and Harm

Jorge Cisneros-González, José Antonio Ondiviela García, Javier Sánchez-Soriano

Abstract

Public administrations are deploying large language model (LLM) assistants that process, summarise, classify and validate citizen-submitted documents. These copilots are exposed to indirect prompt injection: instructions hidden in manipulated documents that reach the model as if they were data. We develop a municipal aid-procedure copilot and evaluate its robustness across six attack objectives, five delivery vectors, five defences and four LLMs, with 3,000 attack evaluations and 1,000

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{cisnerosgonzalez2026indirect,
  title = {{Indirect Prompt Injection in Municipal Document-Processing Copilots: Attacks, Defences and Harm}},
  author = {Jorge Cisneros-González and José Antonio Ondiviela García and Javier Sánchez-Soriano},
  year = {2026},
  month = sep,
  doi = {10.62161/sauc.v12.6399},
  url = {https://doi.org/10.62161/sauc.v12.6399}
}