NIST released the final NIST AI 100-2 E2023 report, a taxonomy and terminology of attacks on and mitigations for machine learning systems. Its generative AI chapter includes separate sections on direct prompt injection and indirect prompt injection, but no dedicated section on agents.
Why it matters
It established the US government vocabulary for prompt injection that later agent security guidance and evaluations reuse.
Key facts
As stated in the sources, with where to find them.
- The E2023 edition's generative AI chapter has Section 3.3 (Direct Prompt Injection Attacks and Mitigations) and Section 3.4 (Indirect Prompt Injection Attacks and Mitigations), with indirect injection subdivided into availability, integrity, privacy and abuse violations.Table of contents, Sections 3.3-3.4
- Authors: Vassilev (NIST), Oprea (Northeastern), Fordyce and Anderson (Robust Intelligence).CSRC publication page
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Mar 24, 2025
Feb 9, 2024
Jan 31, 2025
Nov 17, 2024
Jan 17, 2025
Jan 15, 2025