AION
Concept

Prompt injection

Also known as: prompt injections

8stories this week
8last 30 days
10all time

Timeline

  1. Oct 8, 2026 · Research paper · 1 source
    One Word Opens the Gate: The Option-Channel Attack on Typed Decision Models as Agent Guardrails
    A typed decision model reads a piece of text and returns a probability over caller-defined options, each with a short written definition, generating no text.
  2. Oct 8, 2026 · Research paper · 1 source
    LTBD: Learnable Trust-Boundary Delimiters for Prompt Injection Defense
    To address this, we introduce Learnable Trust-Boundary Delimiters (LTBD), a lightweight defense that explicitly encodes trust boundaries in the input while keeping the LLM parameters unchanged.
  3. Oct 7, 2026 · Research paper · 1 source
    BRANCH: Bypassing Multi-Scanner AI Guardrails
    We propose BRANCH, a bypassing methodology designed for multi-scanner guardrail systems.
  4. Oct 7, 2026 · Research paper · 1 source
    Package Hallucination Attacks on Coding Agents through Prompt Injection in Rule Files
    To bridge this gap, we introduce the package hallucination attack, where an attacker injects malicious prompts into benign rule files to induce coding agents to replace legitimate dependencies with attacker-controlled packages.
  5. Oct 6, 2026 · Research paper · 1 source
    AdvSim2Real : Training Web Agents Against Adaptive Prompt Injection in a Web World Model
    We introduce AdvSim2Real, which co-evolves a task curriculum, an injection adversary, and the agent inside a frozen web world model.
  6. Oct 6, 2026 · Research paper · 1 source
    Secure Speculative Decoding for Large Language Models
    Speculative decoding accelerates inference for a large language model (LLM), referred to as the target model, by first using a smaller model, referred to as the draft model, to generate candidate tokens and then verifying them with the target model for acceptance or rejection.
  7. Oct 6, 2026 · Research paper · 1 source
    RAG-PIBench: A Leakage-Aware Benchmark for Prompt-Injection Detection in Trustworthy RAG Systems
    We introduce RAG-PIBench, a benchmark for RAG-style prompt-injection detection containing 4,876 contextual examples across frozen train, validation, and protected-test splits.
  8. Oct 6, 2026 · Research paper · 1 source
    Surviving the Router: Optimizing Skill Injections for Retrieval and Execution
    To address this limitation, we introduce CORSA (Cluster Optimization for Router-Aware Skill Attacks), a router-aware attack that optimizes skill injections for both retrieval and execution across clusters of related tasks.
  9. Jun 24, 2026 · Product / feature launch · 1 source
    Introducing computer use in Gemini 3.5 Flash
    Introducing computer use in Gemini 3.5 Flash
  10. Jun 16, 2026 · Opinion / analysis · 1 source
    Securing the future of AI agents
    How we’re securing internal systems against increasingly capable and imperfectly aligned AI

Often appears with