{"work":{"id":"977b4683-bba6-49d6-8f3d-496c41cb7fac","openalex_id":"https://openalex.org/W4380353722","doi":"10.48550/arxiv.2306.05499","arxiv_id":"2306.05499","raw_key":null,"title":"Prompt Injection attack against LLM-integrated Applications","authors":null,"authors_text":"Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang","year":2023,"venue":"cs.CR","abstract":"Large Language Models (LLMs), renowned for their superior proficiency in language comprehension and generation, stimulate a vibrant ecosystem of applications around them. However, their extensive assimilation into various services introduces significant security risks. This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications. Initially, we conduct an exploratory analysis on ten commercial applications, highlighting the constraints of current attack strategies in practice. Prompted by these limitations, we subsequently formulate HouYi, a novel black-box prompt injection attack technique, which draws inspiration from traditional web injection attacks. HouYi is compartmentalized into three crucial elements: a seamlessly-incorporated pre-constructed prompt, an injection prompt inducing context partition, and a malicious payload designed to fulfill the attack objectives. Leveraging HouYi, we unveil previously unknown and severe attack outcomes, such as unrestricted arbitrary LLM usage and uncomplicated application prompt theft. We deploy HouYi on 36 actual LLM-integrated applications and discern 31 applications susceptible to prompt injection. 10 vendors have validated our discoveries, including Notion, which has the potential to impact millions of users. Our investigation illuminates both the possible risks of prompt injection attacks and the possible tactics for mitigation.","external_url":"https://arxiv.org/abs/2306.05499","cited_by_count":78,"metadata_source":"pith","metadata_fetched_at":"2026-08-05T02:28:24.338817+00:00","pith_arxiv_id":"2306.05499","created_at":"2026-05-08T21:49:15.399606+00:00","updated_at":"2026-08-05T02:28:24.338817+00:00","title_quality_ok":true,"display_title":"Prompt Injection attack against LLM-integrated Applications","render_title":"Prompt Injection attack against LLM-integrated Applications"},"hub":{"state":{"work_id":"977b4683-bba6-49d6-8f3d-496c41cb7fac","tier":"super_hub","tier_reason":"100+ Pith inbound or 10,000+ external citations","pith_inbound_count":100,"external_cited_by_count":78,"distinct_field_count":13,"first_pith_cited_at":"2023-09-19T02:19:48+00:00","last_pith_cited_at":"2026-07-09T12:18:40+00:00","author_build_status":"needed","summary_status":"needed","contexts_status":"needed","graph_status":"needed","ask_index_status":"needed","reader_status":"not_needed","recognition_status":"not_needed","updated_at":"2026-08-22T22:39:18.955426+00:00","tier_text":"super_hub"},"tier":"super_hub","role_counts":[{"context_role":"background","n":21},{"context_role":"baseline","n":1},{"context_role":"method","n":1}],"polarity_counts":[{"context_polarity":"background","n":18},{"context_polarity":"support","n":3},{"context_polarity":"baseline","n":1},{"context_polarity":"use_method","n":1}],"runs":{"context_extract":{"job_type":"context_extract","status":"succeeded","result":{"enqueued_papers":25},"error":null,"updated_at":"2026-05-14T15:11:59.659809+00:00"},"graph_features":{"job_type":"graph_features","status":"succeeded","result":{"co_cited":[{"title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","work_id":"3322fa86-1768-4677-8425-dd326b45e078","shared_citers":18},{"title":"Ignore Previous Prompt: Attack Techniques For Language Models","work_id":"a7c5b6ec-3407-4330-96c8-3fc58e7d410b","shared_citers":13},{"title":"ReAct: Synergizing Reasoning and Acting in Language Models","work_id":"407a2351-25f1-497d-b611-f77d0292a8e6","shared_citers":9},{"title":"Defeating Prompt Injections by Design","work_id":"86405b86-1c51-4042-9b04-aff0b6541411","shared_citers":8},{"title":"Schmotz, L","work_id":"457096f5-b6b3-42da-ac50-e29571f908bb","shared_citers":8},{"title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","shared_citers":8},{"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","shared_citers":7},{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","work_id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","shared_citers":7},{"title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","work_id":"7b1b672f-e6b4-4df9-aa8b-3396a2eb8b16","shared_citers":6},{"title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","shared_citers":6},{"title":"Gemini: A Family of Highly Capable Multimodal Models","work_id":"83f7c85b-3f11-450f-ac0c-64d9745220b2","shared_citers":6},{"title":"Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents","work_id":"31ff5463-bfee-4ce3-9d67-bd663318c94c","shared_citers":6},{"title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","work_id":"93844332-869b-448c-a1be-35466150b1b2","shared_citers":6},{"title":"Qwen3 Technical Report","work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e","shared_citers":6},{"title":"The Llama 3 Herd of Models","work_id":"1549a635-88af-4ac1-acfe-51ae7bb53345","shared_citers":6},{"title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","shared_citers":5},{"title":"Agent skills in the wild: An empirical study of security vulnerabilities at scale","work_id":"0780d782-7977-4d63-a1f2-3ae587a49c98","shared_citers":5},{"title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","work_id":"5cbfcda4-ec26-44e4-be60-e1525956d71d","shared_citers":5},{"title":"Promptarmor: Simple yet effective prompt injection defenses","work_id":"a555d845-f54e-4efb-8504-b885d3481efa","shared_citers":5},{"title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","work_id":"b95e7447-320c-4c85-b5d0-3708cc2cc72e","shared_citers":5},{"title":"WebGPT: Browser-assisted question-answering with human feedback","work_id":"e25ef3e1-4848-4cb9-bf28-67a420591165","shared_citers":5},{"title":"AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","work_id":"3b676de6-edef-4976-a8b5-082d4ff50867","shared_citers":4},{"title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","work_id":"db5870ca-177b-4d1d-a08d-ee5ceab17fe3","shared_citers":4},{"title":"Constitutional AI: Harmlessness from AI Feedback","work_id":"faaaa4e0-2676-4fac-a0b4-99aef10d2095","shared_citers":4}],"time_series":[{"n":3,"year":2024},{"n":42,"year":2026}],"dependency_candidates":[]},"error":null,"updated_at":"2026-05-14T15:11:52.066492+00:00"},"identity_refresh":{"job_type":"identity_refresh","status":"succeeded","result":{"items":[{"title":"Qwen3 Technical Report","outcome":"unchanged","work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e","resolver":"local_arxiv","confidence":0.98,"old_work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e"}],"counts":{"fixed":0,"merged":0,"unchanged":1,"quarantined":0,"needs_external_resolution":0},"errors":[],"attempted":1},"error":null,"updated_at":"2026-05-14T15:11:54.387718+00:00"},"summary_claims":{"job_type":"summary_claims","status":"succeeded","result":{"title":"Prompt Injection attack against LLM-integrated Applications","claims":[{"claim_text":"Large Language Models (LLMs), renowned for their superior proficiency in language comprehension and generation, stimulate a vibrant ecosystem of applications around them. However, their extensive assimilation into various services introduces significant security risks. This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications. Initially, we conduct an exploratory analysis on ten commercial applications, highlighting the constraints of current attack strategies in practice. Prompted by these limitations, we subsequently formulate","claim_type":"abstract","evidence_strength":"source_metadata"}],"why_cited":"Pith tracks Prompt Injection attack against LLM-integrated Applications because it crossed a citation-hub threshold.","role_counts":[]},"error":null,"updated_at":"2026-05-14T15:12:02.669677+00:00"}},"summary":{"title":"Prompt Injection attack against LLM-integrated Applications","claims":[{"claim_text":"Large Language Models (LLMs), renowned for their superior proficiency in language comprehension and generation, stimulate a vibrant ecosystem of applications around them. However, their extensive assimilation into various services introduces significant security risks. This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications. Initially, we conduct an exploratory analysis on ten commercial applications, highlighting the constraints of current attack strategies in practice. Prompted by these limitations, we subsequently formulate","claim_type":"abstract","evidence_strength":"source_metadata"}],"why_cited":"Pith tracks Prompt Injection attack against LLM-integrated Applications because it crossed a citation-hub threshold.","role_counts":[]},"graph":{"co_cited":[{"title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","work_id":"3322fa86-1768-4677-8425-dd326b45e078","shared_citers":18},{"title":"Ignore Previous Prompt: Attack Techniques For Language Models","work_id":"a7c5b6ec-3407-4330-96c8-3fc58e7d410b","shared_citers":13},{"title":"ReAct: Synergizing Reasoning and Acting in Language Models","work_id":"407a2351-25f1-497d-b611-f77d0292a8e6","shared_citers":9},{"title":"Defeating Prompt Injections by Design","work_id":"86405b86-1c51-4042-9b04-aff0b6541411","shared_citers":8},{"title":"Schmotz, L","work_id":"457096f5-b6b3-42da-ac50-e29571f908bb","shared_citers":8},{"title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","shared_citers":8},{"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","shared_citers":7},{"title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","work_id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","shared_citers":7},{"title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","work_id":"7b1b672f-e6b4-4df9-aa8b-3396a2eb8b16","shared_citers":6},{"title":"Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models","work_id":"0a458c42-fb17-4655-82ad-c93057550c76","shared_citers":6},{"title":"Gemini: A Family of Highly Capable Multimodal Models","work_id":"83f7c85b-3f11-450f-ac0c-64d9745220b2","shared_citers":6},{"title":"Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents","work_id":"31ff5463-bfee-4ce3-9d67-bd663318c94c","shared_citers":6},{"title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","work_id":"93844332-869b-448c-a1be-35466150b1b2","shared_citers":6},{"title":"Qwen3 Technical Report","work_id":"25a4e30c-1232-48e7-9925-02fa12ba7c9e","shared_citers":6},{"title":"The Llama 3 Herd of Models","work_id":"1549a635-88af-4ac1-acfe-51ae7bb53345","shared_citers":6},{"title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","shared_citers":5},{"title":"Agent skills in the wild: An empirical study of security vulnerabilities at scale","work_id":"0780d782-7977-4d63-a1f2-3ae587a49c98","shared_citers":5},{"title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","work_id":"5cbfcda4-ec26-44e4-be60-e1525956d71d","shared_citers":5},{"title":"Promptarmor: Simple yet effective prompt injection defenses","work_id":"a555d845-f54e-4efb-8504-b885d3481efa","shared_citers":5},{"title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","work_id":"b95e7447-320c-4c85-b5d0-3708cc2cc72e","shared_citers":5},{"title":"WebGPT: Browser-assisted question-answering with human feedback","work_id":"e25ef3e1-4848-4cb9-bf28-67a420591165","shared_citers":5},{"title":"AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","work_id":"3b676de6-edef-4976-a8b5-082d4ff50867","shared_citers":4},{"title":"Baseline Defenses for Adversarial Attacks Against Aligned Language Models","work_id":"db5870ca-177b-4d1d-a08d-ee5ceab17fe3","shared_citers":4},{"title":"Constitutional AI: Harmlessness from AI Feedback","work_id":"faaaa4e0-2676-4fac-a0b4-99aef10d2095","shared_citers":4}],"time_series":[{"n":3,"year":2024},{"n":42,"year":2026}],"dependency_candidates":[]},"authors":[]}}