Chronicle/Defense & research

LLMail-Inject releases data from an adaptive prompt injection challenge against an email agent

DefenseDatasetSignificance assistant-drafted

Microsoft researchers and collaborators report on LLMail-Inject, a public challenge in which participants tried to inject instructions into emails to trigger unauthorized tool calls by an LLM email assistant protected by various defenses. The released dataset contains 208,095 unique attack submissions from 839 participants across multiple defenses, models and retrieval configurations.

Why it matters

It provides a large public corpus of adaptive, human-crafted injections for testing defenses.

Key facts

As stated in the sources, with where to find them.

  • 208,095 unique attack submissions from 839 participants.Abstract
  • Microsoft's MSRC post describes the open dataset as over 370,000 prompts from 800+ participants (a different count than the paper's unique submissions).MSRC post, research section

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records