{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:AKF5Z5IPEYDRDS2MTERZNUZCLG","short_pith_number":"pith:AKF5Z5IP","schema_version":"1.0","canonical_sha256":"028bdcf50f260711cb4c992396d3225981613ab57121896f59da0373f5001b14","source":{"kind":"arxiv","id":"2410.08776","version":2},"attestation_state":"computed","paper":{"title":"F2A: An Innovative Approach for Prompt Injection by Utilizing Feign Security Detection Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Yupeng Ren","submitted_at":"2024-10-11T12:49:05Z","abstract_excerpt":"With the rapid development of Large Language Models (LLMs), numerous mature applications of LLMs have emerged in the field of content safety detection. However, we have found that LLMs exhibit blind trust in safety detection agents. The general LLMs can be compromised by hackers with this vulnerability. Hence, this paper proposed an attack named Feign Agent Attack (F2A).Through such malicious forgery methods, adding fake safety detection results into the prompt, the defense mechanism of LLMs can be bypassed, thereby obtaining harmful content and hijacking the normal conversation. Continually, "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2410.08776","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-11T12:49:05Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"5c350f87c62ee102bb673df9c6360879461da634c0515ad743e20b15b7cbf5de","abstract_canon_sha256":"341b9d3ead9a6e6de7fc833f65de47bb669eff3324b3d5e0a63fec47320af988"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:20:04.930282Z","signature_b64":"4EiEVM5I0WrhAD5obvXflfyas8N9rrca7MO2UkCFAQeF+22sAFAus1kox0rs/Ipywru5XYooLYN3NREV3OsiDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"028bdcf50f260711cb4c992396d3225981613ab57121896f59da0373f5001b14","last_reissued_at":"2026-07-05T09:20:04.929851Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:20:04.929851Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"F2A: An Innovative Approach for Prompt Injection by Utilizing Feign Security Detection Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Yupeng Ren","submitted_at":"2024-10-11T12:49:05Z","abstract_excerpt":"With the rapid development of Large Language Models (LLMs), numerous mature applications of LLMs have emerged in the field of content safety detection. However, we have found that LLMs exhibit blind trust in safety detection agents. The general LLMs can be compromised by hackers with this vulnerability. Hence, this paper proposed an attack named Feign Agent Attack (F2A).Through such malicious forgery methods, adding fake safety detection results into the prompt, the defense mechanism of LLMs can be bypassed, thereby obtaining harmful content and hijacking the normal conversation. Continually, "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2410.08776","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.08776/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2410.08776","created_at":"2026-07-05T09:20:04.929903+00:00"},{"alias_kind":"arxiv_version","alias_value":"2410.08776v2","created_at":"2026-07-05T09:20:04.929903+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.08776","created_at":"2026-07-05T09:20:04.929903+00:00"},{"alias_kind":"pith_short_12","alias_value":"AKF5Z5IPEYDR","created_at":"2026-07-05T09:20:04.929903+00:00"},{"alias_kind":"pith_short_16","alias_value":"AKF5Z5IPEYDRDS2M","created_at":"2026-07-05T09:20:04.929903+00:00"},{"alias_kind":"pith_short_8","alias_value":"AKF5Z5IP","created_at":"2026-07-05T09:20:04.929903+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG","json":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG.json","graph_json":"https://pith.science/api/pith-number/AKF5Z5IPEYDRDS2MTERZNUZCLG/graph.json","events_json":"https://pith.science/api/pith-number/AKF5Z5IPEYDRDS2MTERZNUZCLG/events.json","paper":"https://pith.science/paper/AKF5Z5IP"},"agent_actions":{"view_html":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG","download_json":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG.json","view_paper":"https://pith.science/paper/AKF5Z5IP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2410.08776&json=true","fetch_graph":"https://pith.science/api/pith-number/AKF5Z5IPEYDRDS2MTERZNUZCLG/graph.json","fetch_events":"https://pith.science/api/pith-number/AKF5Z5IPEYDRDS2MTERZNUZCLG/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG/action/storage_attestation","attest_author":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG/action/author_attestation","sign_citation":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG/action/citation_signature","submit_replication":"https://pith.science/pith/AKF5Z5IPEYDRDS2MTERZNUZCLG/action/replication_record"}},"created_at":"2026-07-05T09:20:04.929903+00:00","updated_at":"2026-07-05T09:20:04.929903+00:00"}