Preliminary research
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Indirect prompt injection is usually studied without the hardest step: an unoptimised payload is rarely retrieved under natural queries, so its real impact stays unclear. The malicious content is split into a trigger fragment that guarantees retrieval and an attack fragment carrying the objective, and a black-box algorithm builds a compact trigger that pulls any attack fragment into the context.
Record
- Researcher
- Hongyan Chang, Ergute Bao, Xinjian Luo and Ting Yu
- Published by
- usenix.org
- Topic
- Injection
In the archive
Related sources
- Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems (Paper) Whitepaper
- Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
Tags
This page is the archive's own catalogue record. The research is the work of Hongyan Chang, Ergute Bao, Xinjian Luo and Ting Yu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .