arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.07808cs.CRcs.AI

提示注入的剖析:用于结构化分析的组件模型

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis

Jeremy McHugh

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出七个组件的提示注入结构化分析模型,统一相关分类法,结合实例与CTI模式,助力标记、分析提示注入攻击。

中文摘要 AI 辅助

提示注入自2022年首次被发现已过去四年,尽管智能体能力不断提升,且威胁行为者嵌入注入内容以破坏AI辅助安全分析,但攻击仍主要以逐字字符串形式记录,而非结构化漏洞利用。本文将提示注入产物的结构形式化,使防御者、红队人员和网络威胁情报(CTI)团队无需依赖脆弱的字符串匹配即可对攻击进行标记、比较和变异。由于大型语言模型将多样的自然语言实现编译为相同的可执行操作,标记必须追踪攻击者意图(工具目标、漏洞点及效果),而非表面措辞。我们提出一个包含七个组件的模型(载体、传递向量、隐藏、上下文中断、权限提升、有效载荷及返回通道),由五个产物字段和两个环境字段组成。该框架统一了HOUYI的有效载荷分解、Promptware杀伤链及活动分类法部分解决的角色,同时将ReNeLLM等最小越狱框架表述为在受限子空间上的投影。我们提供了清晰的标记规则、直接映射到行业CTI模式的逻辑分析记录、包含EchoLeak(CVE-2025-32711)及一个真实世界恶意软件AI规避样本的示例,以及一个说明性智能体流程图。

英文摘要

Four years after prompt injection was first identified in 2022, attacks are still predominantly documented as verbatim strings rather than structured exploits, despite advancing agent capabilities and threat actors embedding injections to subvert AI-assisted security analysis. This paper formalizes the structure of prompt-injection artifacts, enabling defenders, red teamers, and cyber threat intelligence (CTI) teams to label, compare, and mutate attacks without relying on fragile string matching. Because large language models compile varied natural-language realizations into identical executable actions, labeling must track attacker intent (tool targets, sinks, and effects) rather than surface wording. We propose a seven-component model (carrier, delivery vector, concealment, context-break, privilege escalation, payload, and return channel) consisting of five artifact fields and two environment fields. This framework unifies roles partially addressed by HOUYI's payload decomposition, the Promptware Kill Chain, and campaign taxonomies, while framing minimal jailbreak frameworks like ReNeLLM as projections onto a restricted subspace. We provide clear labeling rules, a logical analysis record mapping directly to industry CTI schemas, worked examples including EchoLeak (CVE-2025-32711) and an in-the-wild malware AI-evasion sample, and an illustrative agentic flowchart.

发表机构

  • Preamble, Inc.(普雷安布尔公司)

机构由 AI 辅助整理,请以论文原文为准。

↑