Preliminary research
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Indirect prompt injection is usually studied without the hardest step: an unoptimised payload is rarely retrieved under natural queries, so its real impact stays unclear. The malicious content is split into a trigger fragment that guarantees retrieval and an attack fragment carrying the objective, and a black-box algorithm builds a compact trigger that pulls any attack fragment into the context.
Record
- Researcher
- Hongyan Chang, Ergute Bao, Xinjian Luo and Ting Yu
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Hongyan Chang, Ergute Bao, Xinjian Luo and Ting Yu, first published at the original source. Preserved copies are kept so the citation survives its host.