demonstrates-instructions-planted-retrieved-content-can-hijack-real
mechanismsingle paper

Demonstrates that instructions planted in retrieved content can hijack real LLM-integrated applications for data theft and manipulation.

Capability: Following instructions hidden in data

Sources

Status: activeLast checked: 2026-09-03Evidence activityHow much the field cites the sources under this claimvery heavily cited in the last 12 months1000+ in 12mo · 1870 total — Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Contest this claim

Disagreeing is the most useful thing you can do here. Both sides of every contested claim in this catalog were assembled by the same person, which is its weakest point.