September 2026Unreviewed
ShadowCode: Toward (Automatic) External Prompt Injection Attack Against Code LLMs
Yuchen Yang, Yi-Ming Li, H. Yao, Bing-Run Yang, Yiling He, Tianwei Zhang, Dacheng Tao, Z. Qin
IEEE Transactions on Dependable and Secure Computing
Abstract
Recent advancements have led to the widespread adoption of code-oriented large language models (Code LLMs) for programming tasks. Despite their success in deployment, their security research is left far behind. This paper introduces a new attack paradigm: (automatic) external prompt injection against Code LLMs, where attackers generate concise, non-functional induced perturbations and inject them within a victim’s code context. These induced perturbations can be disseminated through commonly use
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@article{yang2026shadowcode,
title = {{ShadowCode: Toward (Automatic) External Prompt Injection Attack Against Code LLMs}},
author = {Yuchen Yang and Yi-Ming Li and H. Yao and Bing-Run Yang and Yiling He and Tianwei Zhang and Dacheng Tao and Z. Qin},
year = {2026},
month = sep,
journal = {IEEE Transactions on Dependable and Secure Computing},
doi = {10.1109/TDSC.2026.3703498},
url = {https://www.semanticscholar.org/paper/f7d0fe61df3d82faa00b5379d47ee364d85f4d2a}
}