{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:SGMOKGMSJ6GGOAEKRAAJORDLX6","short_pith_number":"pith:SGMOKGMS","schema_version":"1.0","canonical_sha256":"9198e519924f8c67008a880097446bbf804c336b27c6afd526c35147e2ca57c0","source":{"kind":"arxiv","id":"2402.00898","version":1},"attestation_state":"computed","paper":{"title":"An Early Categorization of Prompt Injection Attacks on Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Alisia Marianne Michel, Jason Bennett Thatcher, Raghava Rao Mukkamala, Sippo Rossi","submitted_at":"2024-01-31T19:52:00Z","abstract_excerpt":"Large language models and AI chatbots have been at the forefront of democratizing artificial intelligence. However, the releases of ChatGPT and other similar tools have been followed by growing concerns regarding the difficulty of controlling large language models and their outputs. Currently, we are witnessing a cat-and-mouse game where users attempt to misuse the models with a novel attack called prompt injections. In contrast, the developers attempt to discover the vulnerabilities and block the attacks simultaneously. In this paper, we provide an overview of these emergent threats and prese"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.00898","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-01-31T19:52:00Z","cross_cats_sorted":["cs.CL","cs.LG"],"title_canon_sha256":"4fb60857dfa75f0c80bb55767c0bcce3f2f1ebbc1f413a4b9c19b849c9ce530b","abstract_canon_sha256":"06a85644eca3c85e9b73f1267bcf82ff3a8a00af3905c568bf9709f7469f68d3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:40:27.768163Z","signature_b64":"22cz5qpj6lGKnTBMOSFrJGpxHEoMP81qaw87Sw3xjO9bFcUGPCZ1Q/lQu/zKC2pppBqyCpGgZeV6yRNS28WDDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9198e519924f8c67008a880097446bbf804c336b27c6afd526c35147e2ca57c0","last_reissued_at":"2026-07-05T07:40:27.767632Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:40:27.767632Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"An Early Categorization of Prompt Injection Attacks on Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Alisia Marianne Michel, Jason Bennett Thatcher, Raghava Rao Mukkamala, Sippo Rossi","submitted_at":"2024-01-31T19:52:00Z","abstract_excerpt":"Large language models and AI chatbots have been at the forefront of democratizing artificial intelligence. However, the releases of ChatGPT and other similar tools have been followed by growing concerns regarding the difficulty of controlling large language models and their outputs. Currently, we are witnessing a cat-and-mouse game where users attempt to misuse the models with a novel attack called prompt injections. In contrast, the developers attempt to discover the vulnerabilities and block the attacks simultaneously. In this paper, we provide an overview of these emergent threats and prese"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.00898","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.00898/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.00898","created_at":"2026-07-05T07:40:27.767700+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.00898v1","created_at":"2026-07-05T07:40:27.767700+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.00898","created_at":"2026-07-05T07:40:27.767700+00:00"},{"alias_kind":"pith_short_12","alias_value":"SGMOKGMSJ6GG","created_at":"2026-07-05T07:40:27.767700+00:00"},{"alias_kind":"pith_short_16","alias_value":"SGMOKGMSJ6GGOAEK","created_at":"2026-07-05T07:40:27.767700+00:00"},{"alias_kind":"pith_short_8","alias_value":"SGMOKGMS","created_at":"2026-07-05T07:40:27.767700+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.30534","citing_title":"Strengthening Polymorphic Prompt Assembling: Dynamic Separator Generation Against Emerging Prompt Injection Attacks","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":98,"is_internal_anchor":false},{"citing_arxiv_id":"2601.04740","citing_title":"StealthGraph: Exposing Domain-Specific Risks in LLMs through Knowledge-Graph-Guided Harmful Prompt Generation","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2605.04522","citing_title":"DAO-enabled decentralized physical AI: A new paradigm for human-machine collaboration","ref_index":72,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6","json":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6.json","graph_json":"https://pith.science/api/pith-number/SGMOKGMSJ6GGOAEKRAAJORDLX6/graph.json","events_json":"https://pith.science/api/pith-number/SGMOKGMSJ6GGOAEKRAAJORDLX6/events.json","paper":"https://pith.science/paper/SGMOKGMS"},"agent_actions":{"view_html":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6","download_json":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6.json","view_paper":"https://pith.science/paper/SGMOKGMS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.00898&json=true","fetch_graph":"https://pith.science/api/pith-number/SGMOKGMSJ6GGOAEKRAAJORDLX6/graph.json","fetch_events":"https://pith.science/api/pith-number/SGMOKGMSJ6GGOAEKRAAJORDLX6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6/action/storage_attestation","attest_author":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6/action/author_attestation","sign_citation":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6/action/citation_signature","submit_replication":"https://pith.science/pith/SGMOKGMSJ6GGOAEKRAAJORDLX6/action/replication_record"}},"created_at":"2026-07-05T07:40:27.767700+00:00","updated_at":"2026-07-05T07:40:27.767700+00:00"}