May 2026Unreviewed
Formal Operational Models for Protecting Web Interfaces of Legal LLM Systems from Prompt Injection and Insecure Output Handling
Grigorii Danileiko
International Journal of Advanced Artificial Intelligence Research
Abstract
The proliferation of large language model (LLM) systems in legal technology platforms has created a new class of web-interface security vulnerabilities that existing application security frameworks address incompletely. This paper examines prompt injection and insecure output handling as the two primary attack surfaces for legal LLM web applications, with particular attention to contract lifecycle management systems that expose natural-language interfaces to privileged document repositories. Dra
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@article{danileiko2026formal,
title = {{Formal Operational Models for Protecting Web Interfaces of Legal LLM Systems from Prompt Injection and Insecure Output Handling}},
author = {Grigorii Danileiko},
year = {2026},
month = may,
journal = {International Journal of Advanced Artificial Intelligence Research},
doi = {10.55640/ijaair-v03i05-03},
url = {https://doi.org/10.55640/ijaair-v03i05-03}
}