{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:VSW4I5D4W3IS5OOZJ4S26G32LK","short_pith_number":"pith:VSW4I5D4","schema_version":"1.0","canonical_sha256":"acadc4747cb6d12eb9d94f25af1b7a5abac0c08b9e68f8151c39c633cf0545f2","source":{"kind":"arxiv","id":"2508.19287","version":1},"attestation_state":"computed","paper":{"title":"Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chunhua Su, Qingkui Zeng, Teruaki Kitasuka, Toru Nakanishi, Weiyu Wang, Zhuotao Lian","submitted_at":"2025-08-25T05:20:11Z","abstract_excerpt":"Large Language Models (LLMs) are widely deployed in applications that accept user-submitted content, such as uploaded documents or pasted text, for tasks like summarization and question answering. In this paper, we identify a new class of attacks, prompt in content injection, where adversarial instructions are embedded in seemingly benign inputs. When processed by the LLM, these hidden prompts can manipulate outputs without user awareness or system compromise, leading to biased summaries, fabricated claims, or misleading suggestions. We demonstrate the feasibility of such attacks across popula"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.19287","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-08-25T05:20:11Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"eac5893f6bd2192b4cce17a40241c135379bf63f1988ab27b6d565ba714cc03a","abstract_canon_sha256":"fc27919c8739b4e0ebde943eda8af3e3f070c83bc51fc5599d52a5304f462cc6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:59:42.426035Z","signature_b64":"qWkLVZ6MwT40aloCkys2LPkQrkus+t/qRuMuF/dEuFXhVun68SbZf8kJaUuwo2VFTS8N584BuCvgTebfLb8rBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"acadc4747cb6d12eb9d94f25af1b7a5abac0c08b9e68f8151c39c633cf0545f2","last_reissued_at":"2026-07-05T11:59:42.425588Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:59:42.425588Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chunhua Su, Qingkui Zeng, Teruaki Kitasuka, Toru Nakanishi, Weiyu Wang, Zhuotao Lian","submitted_at":"2025-08-25T05:20:11Z","abstract_excerpt":"Large Language Models (LLMs) are widely deployed in applications that accept user-submitted content, such as uploaded documents or pasted text, for tasks like summarization and question answering. In this paper, we identify a new class of attacks, prompt in content injection, where adversarial instructions are embedded in seemingly benign inputs. When processed by the LLM, these hidden prompts can manipulate outputs without user awareness or system compromise, leading to biased summaries, fabricated claims, or misleading suggestions. We demonstrate the feasibility of such attacks across popula"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.19287","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.19287/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.19287","created_at":"2026-07-05T11:59:42.425650+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.19287v1","created_at":"2026-07-05T11:59:42.425650+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.19287","created_at":"2026-07-05T11:59:42.425650+00:00"},{"alias_kind":"pith_short_12","alias_value":"VSW4I5D4W3IS","created_at":"2026-07-05T11:59:42.425650+00:00"},{"alias_kind":"pith_short_16","alias_value":"VSW4I5D4W3IS5OOZ","created_at":"2026-07-05T11:59:42.425650+00:00"},{"alias_kind":"pith_short_8","alias_value":"VSW4I5D4","created_at":"2026-07-05T11:59:42.425650+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2512.20405","citing_title":"ChatGPT: Excellent Paper! Accept It. Editor: Imposter Found! Review Rejected","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK","json":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK.json","graph_json":"https://pith.science/api/pith-number/VSW4I5D4W3IS5OOZJ4S26G32LK/graph.json","events_json":"https://pith.science/api/pith-number/VSW4I5D4W3IS5OOZJ4S26G32LK/events.json","paper":"https://pith.science/paper/VSW4I5D4"},"agent_actions":{"view_html":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK","download_json":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK.json","view_paper":"https://pith.science/paper/VSW4I5D4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.19287&json=true","fetch_graph":"https://pith.science/api/pith-number/VSW4I5D4W3IS5OOZJ4S26G32LK/graph.json","fetch_events":"https://pith.science/api/pith-number/VSW4I5D4W3IS5OOZJ4S26G32LK/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK/action/storage_attestation","attest_author":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK/action/author_attestation","sign_citation":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK/action/citation_signature","submit_replication":"https://pith.science/pith/VSW4I5D4W3IS5OOZJ4S26G32LK/action/replication_record"}},"created_at":"2026-07-05T11:59:42.425650+00:00","updated_at":"2026-07-05T11:59:42.425650+00:00"}