Collected research
New ways of breaking app-integrated LLMs
Demonstrates indirect prompt injection against application-integrated LLMs: instructions hidden in a web page, email or source file that the model retrieves become commands, letting an attacker remote-control the assistant, exfiltrate or alter user data, persist across sessions through the agent's memory, spread to other agents, and poison code completion.
Record
- Researcher
- Kai Greshake
- Published by
- GitHub
- Format
- Repository
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Kai Greshake, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .