Authors from Invariant Labs, IBM, ETH Zurich, Swisscom, Google, Microsoft and others propose six design patterns that limit what injected text can do, such as action-selector, plan-then-execute, dual LLM, LLM map-reduce, code-then-execute and context minimization. They discuss utility and security trade-offs and illustrate the patterns with ten application case studies.
Why it matters
It gives builders architecture-level mitigations that do not depend on the model detecting injections.
Key facts
As stated in the sources, with where to find them.
- Six patterns defined; ten case studies including an SQL agent, email and calendar assistant, and software engineering agent.Section 3.1; Section 4
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Aug 6, 2025
Aug 6, 2025
May 26, 2025
Jun 19, 2024
Mar 24, 2025
Aug 1, 2025