Chronicle/Attacks & incidents

Researchers define indirect prompt injection against LLM-integrated apps including Bing Chat

AttackPaperSignificance assistant-drafted

Greshake et al. describe indirect prompt injection, where instructions planted in data an LLM application retrieves are treated as commands. The paper demonstrates the attack class against Bing's GPT-4 powered chat, code-completion engines, and synthetic GPT-4 applications, and catalogs impacts including data theft, worming, and unauthorized API calls.

Why it matters

It is the reference point for the attack class behind most later agent, connector, and browser-agent disclosures in this corpus.

Key facts

As stated in the sources, with where to find them.

  • Demonstrated targets include Bing's GPT-4 powered Chat and code-completion engines, plus synthetic applications built on GPT-4.Abstract
  • Impact categories named include data theft, worming, information ecosystem contamination, and unauthorized API invocation.Abstract

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records