Understanding Prompt Injection
A security-oriented introduction to prompt injection in LLM applications.
Understanding Prompt Injection
Prompt injection occurs when untrusted input influences an LLM in ways that conflict with the application's intended instructions or security boundaries.
AI security testing should be performed only against systems you are authorized to assess.
Threat Model
Separate trusted instructions, user-controlled content, retrieved data and tool outputs.
Testing
Focus on whether untrusted content can alter model behavior, expose protected context, or cause unsafe tool use.
Mitigation
Use strong application-level authorization, tool permission boundaries, input provenance, output validation and least privilege. Do not assume that a system prompt is an access-control boundary.
Conclusion
LLM security is application security with an unreliable natural-language component in the middle. Treat model output as untrusted data.
Related Research
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.
Understanding HTTP Request Smuggling
A methodology for analyzing parser inconsistencies between HTTP components.
Getting Started With Frida
An introduction to runtime instrumentation for authorized application research.