Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
突破检索障碍:为LLM系统设计的野外间接提示注入
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
AI总结 本研究提出了一种高效且低成本的黑盒攻击算法,通过分解恶意内容为触发片段和攻击片段,实现了对LLM系统的间接提示注入攻击,揭示了检索过程中存在的关键安全漏洞。
AI 大模型
大模型对齐、安全、越狱、红队、提示注入和可信评测。
突破检索障碍:为LLM系统设计的野外间接提示注入
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
AI总结 本研究提出了一种高效且低成本的黑盒攻击算法,通过分解恶意内容为触发片段和攻击片段,实现了对LLM系统的间接提示注入攻击,揭示了检索过程中存在的关键安全漏洞。
对抗间接提示注入的指令检测
机构 * Renmin University of China(中国人民大学) ; Peking University Shenzhen Graduate School(北京大学深圳研究生院) ; Wuhan University(武汉大学) ; University of Science and Technology of China(中国科学技术大学) ; Hong Kong University of Science and Technology(香港科技大学) ; Sony AI(索尼人工智能) ; Microsoft Research Asia(微软亚洲研究院)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
AI总结 本文提出InstructDetector,通过检测LLMs行为状态来识别IPI攻击,实现高检测准确率和低攻击成功率。
Comments 16 pages, 4 figures
超越基准:对抗提示注入攻击的创新防御
机构 * Dept. of CS, SDS BRAC University(计算机科学系,BRAC大学) ; Dept. of CSE, SDS BRAC University(计算机工程系,BRAC大学)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
AI总结 本文提出创新防御机制,通过迭代优化防御提示,有效缓解LLM中的目标劫持漏洞,提升小型开源模型的安全性与部署效率。
Comments 10 pages, 4 figures
针对提示注入攻击的多智能体LLM防御管道
机构 * School of Computing, Wichita State University, Kansas, USA(威斯康星州立大学计算机学院) ; College of Engineering and Computer Sciences, Marshall University, Huntington, WV, USA(马歇尔大学工程与计算机科学学院) ; Department of Computer Science and Engineering, University of Rajshahi, Bangladesh(拉贾沙希大学计算机科学与工程系) ; Department of Computer Science and Engineering, American International University-Bangladesh, Dhaka, Bangladesh(美国国际大学-孟加拉国计算机科学与工程系) ; School of Computer Science and Engineering, The University of Aizu, Aizuwakamatsu, Japan(立命馆大学计算机科学与工程学院)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
AI总结 本文提出了一种多智能体防御框架,通过协调的LLM代理实时检测并中和提示注入攻击,显著提升了安全性和系统功能。
Comments Accepted at the 11th IEEE WIECON-ECE 2025
DeepSeek的WEIRD行为:大型语言模型的文化契合与提示语言和文化提示的影响
机构 * School of Data Science University of Virginia(数据科学学院 芝加哥大学)
专题命中 提示注入 :alignment(title,abstract);分类 cs.CL
AI总结 研究探讨了大型语言模型在不同文化提示下的对齐行为,发现DeepSeek-V3和GPT-5在美文化下表现突出,而GPT-4在英文化下更接近中国,文化提示可调整这种对齐。
通过指令遵循意图分析缓解间接提示注入
机构 * NVIDIA ; University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校) ; Johns Hopkins University(约翰霍普金斯大学)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
AI总结 IntentGuard通过分析指令遵循意图,有效缓解间接提示注入攻击,保持模型性能并降低攻击成功率
探索联邦军事大语言模型中的潜在提示注入攻击及其缓解方法
机构 * Institute of Information & Communications Technology Planning & Evaluation (IITP)-ITRC (Information Technology Research Center)(信息与通信技术规划与评估机构(IITP)-ITRC(信息技术研究中心))
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
AI总结 本文探讨了联邦军事大语言模型中潜在的提示注入攻击问题,提出人机协作框架结合技术和政策措施来缓解相关风险。
Comments Accepted to the 3rd International Workshop on Dataspaces and Digital Twins for Critical Entities and Smart Urban Communities - IEEE BigData 2025
保护AI代理免受提示注入攻击
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
AI总结 本文提出了一种多层防御框架,通过评估RAG系统中的提示注入风险,将攻击成功率降低至8.7%,同时保持高任务性能。
机构 * National University of Singapore(新加坡国立大学) ; Shanghai Jiao Tong University(上海交通大学)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments Distinguished Paper Award in IEEE Symposium on Security and Privacy, 2025. For slides, see https://people.duke.edu/~zg70/code/PromptInjection.pdf
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
机构 * University of California, Santa Barbara(加州大学圣巴bara分校)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments At IEEE S&P 2026
机构 * ELLIS Institute Tübingen(图宾根ELLIS研究所) ; MPI for Intelligent Systems Tübingen(图宾根智能系统研究所) ; AI Center(人工智能中心)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
机构 * Isaac Wu Research Fellow(Isaac Wu 研究员) ; Non-Trivial Ventures(非平凡企业)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments 11 pages, 7 figures
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.CY
Comments Accepted as a poster to Soups 2025
Journal ref The Twenty-First Symposium on Usable Privacy and Security (SOUPS 2025) Poster
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments To appear in IEEE Symposium on Security and Privacy, 2026. For slides, see https://people.duke.edu/~zg70/code/PromptInjection.pdf
机构 * Avihay Cohen
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments 37 pages , 10 figures
机构 * Computing Department of Hong Kong Polytechnic University(香港理工大学计算机系) ; Computing Department, The Hong Kong Polytechnic University(香港理工大学计算机系)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments 13 pages, 8 figures. Submitted to IEEE Transactions on Information Forensics & Security
机构 * Institute for Machine Learning and Analytics (IMLA)(机器学习与分析研究所)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments 8 pages content, 1 page references, 2 figures, Published at AAAI Fall Symposium Series 2025
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.CY
机构 * School of Software Engineering, Huazhong University of Science and Technology(华中科技大学软件学院) ; School of Cyber Science and Engineering, Huazhong University of Science and Technology(华中科技大学网络安全学院) ; College of Computing and Data Science, Nanyang Technological University(南洋理工大学计算与数据科学学院) ; Faculty of Data Science, City University of Macau(澳门城市大学数据科学学院)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments Accepted to EMNLP 2025
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
机构 * UC Berkeley(加州大学伯克利分校) ; UC Santa Barbara(加州大学圣巴巴拉分校) ; Duke University(杜克大学) ; National University of Singapore(新加坡国立大学) ; King Abdulaziz City for Science and Technology(国王阿卜杜勒阿齐兹城市科学技术学院) ; University of Washington(华盛顿大学)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments EMNLP 2025 System Demonstrations Submission
机构 * Preamble, Inc.(Preamble公司)
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
机构 * Invariant Labs ; IBM ; EPFL(苏黎世联邦理工学院) ; ETH Zurich(苏黎世联邦理工学院) ; Swisscom(瑞士通信) ; Google(谷歌) ; ETH AI Center(苏黎世联邦理工学院人工智能中心) ; AppliedAI Institute for Europe(欧洲应用AI研究院) ; Microsoft(微软) ; Lakera
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.LG
专题命中 提示注入 :prompt injection(title,abstract);分类 cs.AI
Comments Updated version with newer models and link to the code