የቴክኒክ መመሪያ

Indirect Prompt Injection

Indirect prompt injection occurs when untrusted content an AI system reads contains instructions intended to alter the system’s behavior, even though the user did not directly provide those instructions.

  • 3 ደቂቃ አንብብ
  • ለመጨረሻ ጊዜ የዘመነው
በዚህ ገጽ ላይ3 ደቂቃ አንብብ
  1. አጠቃላይ እይታ
  2. ጥልቅ ዳይቭ
  3. ስልታዊ ተጽእኖ
  4. The Future of Indirect Prompt Injection
  5. የእውነተኛ-ዓለም አተገባበር
  6. አደጋዎች እና የጥበቃ መንገዶች
  7. የትግበራ ፍኖተ ካርታ
  8. ማሰስዎን ይቀጥሉ
  9. በተደጋጋሚ የሚጠየቁ ጥያቄዎች

አጠቃላይ እይታ

Risk increases when an agent can use tools or access sensitive data, so layered defenses should limit what untrusted content can influence and what actions the agent can take.

ጥልቅ ዳይቭ

A direct prompt injection comes from a user’s message to the model. In an indirect prompt injection, the attacker places instructions in content the system later processes, such as a webpage, email, file, or retrieved document. If an assistant treats that content as instructions rather than data, the content may redirect a task, manipulate a recommendation, or try to make the system expose information or call a tool. The security problem is not limited to a phrase such as “ignore previous instructions.” Any external text may influence model output because models process instructions and data in a shared context. The 2023 Greshake et al. paper demonstrated indirect attacks against LLM-integrated applications that retrieved attacker-controlled content and could alter downstream behavior. OpenAI’s current security guidance likewise describes untrusted text or data attempting to override system instructions and warns that tool access raises the consequences. No single prompt rule completely solves the problem. Defenses include minimizing agent permissions, separating trusted instructions from untrusted content, extracting only validated structured fields, constraining outputs, checking tool arguments in code, and requiring confirmation for consequential actions. Logging, red-teaming, and trace evaluation can reveal failures. These controls reduce attack surface but do not make every model immune. Users should give narrow tasks and review important actions before confirming them. Developers should assume retrieved content may be adversarial, avoid placing it in privileged instruction channels, and keep authorization checks outside the model. Treat content from tools and files as evidence to inspect, not as a source of new authority.

ስልታዊ ተጽእኖ

ወጪ እና በጀት

የስነ-ህንፃ ውሳኔዎች ለዓመታት አፈጻጸምን እና የሥራ ማስኬጃ ወጪዎችን ያንቀሳቅሳሉ.

ግልጽ ውሳኔዎች

የቴክኒክ ትምህርት ቡድኖች አዲሱን ብቻ ሳይሆን ትክክለኛውን ቁልል እንዲመርጡ ይረዳል።

የጥራት ቁጥጥር

የተሻሉ የምህንድስና ምርጫዎች በምርት ውስጥ አስተማማኝነት ክስተቶችን ይቀንሳሉ.

The Future of Indirect Prompt Injection

As agents connect to more browsers, files, and business tools, the number of untrusted content paths will grow. Defenses are likely to combine model training, input provenance, sandboxing, structured data flow, tool permissions, and human confirmation. Attacks will adapt, so red-teaming and monitoring must continue. Future systems should make source trust and pending actions visible, while treating mitigations as risk reduction rather than proof of immunity. Product testing should also include realistic third-party content and changing attack tactics over time.

የእውነተኛ-ዓለም አተገባበር

A web page includes hidden text telling a browser agent to ignore the user and promote that page.

An email asks an assistant with mailbox access to forward private messages to an outside address.

A developer extracts a document title into a validated field instead of copying its full text into a developer prompt.

An agent asks the user to confirm a purchase after checking the recipient and amount.

አደጋዎች እና የጥበቃ መንገዶች

  • አንድ ቤንችማርክን ማሳደግ ሰፋ ያሉ የስርዓት ድክመቶችን ሊደብቅ ይችላል።

  • የመሠረተ ልማት እና የጥገና ወጪዎች ብዙ ጊዜ ዝቅተኛ ናቸው.

  • ስርዓቶች ይበልጥ ውስብስብ ሲሆኑ የደህንነት እና የታዛቢነት ክፍተቶች ሊያድጉ ይችላሉ።

የትግበራ ፍኖተ ካርታ

  1. ከመተግበሩ በፊት የቆይታ፣ የጥራት እና የወጪ ግቦችን ይግለጹ።

  2. ቤንችማርክ በእውነተኛ ጭነት እና የውሂብ ሁኔታዎች።

  3. ለስህተቶች፣ ተንሸራታች እና የተጠቃሚ ተጽእኖ የመሳሪያ ክትትል።

  4. ከመጠኑ በፊት የመመለሻ እና የአደጋ ምላሽ መንገዶችን ያዘጋጁ።

ማሰስዎን ይቀጥሉ

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Indirect Prompt Injection quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

ጥያቄ ጀምር

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

በተደጋጋሚ የሚጠየቁ ጥያቄዎች

What is Indirect Prompt Injection?

Indirect prompt injection occurs when untrusted content an AI system reads contains instructions intended to alter the system’s behavior, even though the user did not directly provide those instructions. Risk increases when an agent can use tools or access sensitive data, so layered defenses should limit what untrusted content can influence and what actions the agent can take.

What makes a prompt injection indirect?

Indirect attacks are embedded in third-party content rather than typed directly by the user.

Which content could carry an indirect prompt injection?

The attack can arrive through external content the assistant reads.

What can an indirect injection try to cause an agent to do?

Research and current security guidance describe behavior changes and downstream tool risks.

Which is a defense-in-depth measure?

Least privilege and external validation constrain what a model can do.

Why use structured outputs for data extracted from an untrusted document?

Structured fields can be checked before passing values downstream.