Greshake et al. describe indirect prompt injection, where instructions planted in data an LLM application retrieves are treated as commands. The paper demonstrates the attack class against Bing's GPT-4 powered chat, code-completion engines, and synthetic GPT-4 applications, and catalogs impacts including data theft, worming, and unauthorized API calls.
Why it matters
It is the reference point for the attack class behind most later agent, connector, and browser-agent disclosures in this corpus.
Key facts
As stated in the sources, with where to find them.
- Demonstrated targets include Bing's GPT-4 powered Chat and code-completion engines, plus synthetic applications built on GPT-4.Abstract
- Impact categories named include data theft, worming, information ecosystem contamination, and unauthorized API invocation.Abstract
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Mar 5, 2024
Jun 19, 2024
Apr 19, 2024
Nov 3, 2023
Mar 24, 2025
Mar 5, 2024