{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:7FXSHDWDJGXLQJ6N74KQXDSWM7","short_pith_number":"pith:7FXSHDWD","schema_version":"1.0","canonical_sha256":"f96f238ec349aeb827cdff150b8e5667f0f8226211f965422d712640965359ce","source":{"kind":"arxiv","id":"2403.03792","version":2},"attestation_state":"computed","paper":{"title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Carmela Troncoso, Dario Pasquini, Martin Strohmeier","submitted_at":"2024-03-06T15:40:30Z","abstract_excerpt":"We introduce a new family of prompt injection attacks, termed Neural Exec. Unlike known attacks that rely on handcrafted strings (e.g., \"Ignore previous instructions and...\"), we show that it is possible to conceptualize the creation of execution triggers as a differentiable search problem and use learning-based methods to autonomously generate them.\n  Our results demonstrate that a motivated adversary can forge triggers that are not only drastically more effective than current handcrafted ones but also exhibit inherent flexibility in shape, properties, and functionality. In this direction, we"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2403.03792","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-03-06T15:40:30Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"ccc201e821b94f626679f697736b276c3face631eb5a50f77cf446b3ee2e176f","abstract_canon_sha256":"f69973a59c5df55ec6f4995968b43922890bbdeea328946fe9f4e58612be7a40"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:14:22.492170Z","signature_b64":"hSrAxdhrQR5llMoSkQlSxtMBlgftE/QAY+5WOI85PIWNR8LK0zgcfKGf5XjFuFi2AQB2CyA6uu4WuWoYjV+/Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f96f238ec349aeb827cdff150b8e5667f0f8226211f965422d712640965359ce","last_reissued_at":"2026-07-05T08:14:22.491659Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:14:22.491659Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Carmela Troncoso, Dario Pasquini, Martin Strohmeier","submitted_at":"2024-03-06T15:40:30Z","abstract_excerpt":"We introduce a new family of prompt injection attacks, termed Neural Exec. Unlike known attacks that rely on handcrafted strings (e.g., \"Ignore previous instructions and...\"), we show that it is possible to conceptualize the creation of execution triggers as a differentiable search problem and use learning-based methods to autonomously generate them.\n  Our results demonstrate that a motivated adversary can forge triggers that are not only drastically more effective than current handcrafted ones but also exhibit inherent flexibility in shape, properties, and functionality. In this direction, we"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2403.03792","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2403.03792/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2403.03792","created_at":"2026-07-05T08:14:22.491723+00:00"},{"alias_kind":"arxiv_version","alias_value":"2403.03792v2","created_at":"2026-07-05T08:14:22.491723+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2403.03792","created_at":"2026-07-05T08:14:22.491723+00:00"},{"alias_kind":"pith_short_12","alias_value":"7FXSHDWDJGXL","created_at":"2026-07-05T08:14:22.491723+00:00"},{"alias_kind":"pith_short_16","alias_value":"7FXSHDWDJGXLQJ6N","created_at":"2026-07-05T08:14:22.491723+00:00"},{"alias_kind":"pith_short_8","alias_value":"7FXSHDWD","created_at":"2026-07-05T08:14:22.491723+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10525","citing_title":"Assessing Automated Prompt Injection Attacks in Agentic Environments","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2409.10102","citing_title":"Trustworthiness in Retrieval-Augmented Generation Systems: A Survey","ref_index":81,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20984","citing_title":"ACE: A Security Architecture for LLM-Integrated App Systems","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23887","citing_title":"Evaluation of Prompt Injection Defenses in Large Language Models","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2406.13352","citing_title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23887","citing_title":"Evaluation of Prompt Injection Defenses in Large Language Models","ref_index":14,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7","json":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7.json","graph_json":"https://pith.science/api/pith-number/7FXSHDWDJGXLQJ6N74KQXDSWM7/graph.json","events_json":"https://pith.science/api/pith-number/7FXSHDWDJGXLQJ6N74KQXDSWM7/events.json","paper":"https://pith.science/paper/7FXSHDWD"},"agent_actions":{"view_html":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7","download_json":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7.json","view_paper":"https://pith.science/paper/7FXSHDWD","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2403.03792&json=true","fetch_graph":"https://pith.science/api/pith-number/7FXSHDWDJGXLQJ6N74KQXDSWM7/graph.json","fetch_events":"https://pith.science/api/pith-number/7FXSHDWDJGXLQJ6N74KQXDSWM7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7/action/storage_attestation","attest_author":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7/action/author_attestation","sign_citation":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7/action/citation_signature","submit_replication":"https://pith.science/pith/7FXSHDWDJGXLQJ6N74KQXDSWM7/action/replication_record"}},"created_at":"2026-07-05T08:14:22.491723+00:00","updated_at":"2026-07-05T08:14:22.491723+00:00"}