Skip to content
Search
paperSeptember 2026Unreviewed

ShadowCode: Toward (Automatic) External Prompt Injection Attack Against Code LLMs

Yuchen Yang, Yi-Ming Li, H. Yao, Bing-Run Yang, Yiling He, Tianwei Zhang, Dacheng Tao, Z. Qin

IEEE Transactions on Dependable and Secure Computing

Abstract

Recent advancements have led to the widespread adoption of code-oriented large language models (Code LLMs) for programming tasks. Despite their success in deployment, their security research is left far behind. This paper introduces a new attack paradigm: (automatic) external prompt injection against Code LLMs, where attackers generate concise, non-functional induced perturbations and inject them within a victim’s code context. These induced perturbations can be disseminated through commonly use

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@article{yang2026shadowcode,
  title = {{ShadowCode: Toward (Automatic) External Prompt Injection Attack Against Code LLMs}},
  author = {Yuchen Yang and Yi-Ming Li and H. Yao and Bing-Run Yang and Yiling He and Tianwei Zhang and Dacheng Tao and Z. Qin},
  year = {2026},
  month = sep,
  journal = {IEEE Transactions on Dependable and Secure Computing},
  doi = {10.1109/TDSC.2026.3703498},
  url = {https://www.semanticscholar.org/paper/f7d0fe61df3d82faa00b5379d47ee364d85f4d2a}
}