September 2026Unreviewed
Indirect Prompt Injection in Municipal Document-Processing Copilots: Attacks, Defences and Harm
Jorge Cisneros-González, José Antonio Ondiviela García, Javier Sánchez-Soriano
Abstract
Public administrations are deploying large language model (LLM) assistants that process, summarise, classify and validate citizen-submitted documents. These copilots are exposed to indirect prompt injection: instructions hidden in manipulated documents that reach the model as if they were data. We develop a municipal aid-procedure copilot and evaluate its robustness across six attack objectives, five delivery vectors, five defences and four LLMs, with 3,000 attack evaluations and 1,000
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{cisnerosgonzalez2026indirect,
title = {{Indirect Prompt Injection in Municipal Document-Processing Copilots: Attacks, Defences and Harm}},
author = {Jorge Cisneros-González and José Antonio Ondiviela García and Javier Sánchez-Soriano},
year = {2026},
month = sep,
doi = {10.62161/sauc.v12.6399},
url = {https://doi.org/10.62161/sauc.v12.6399}
}