Injection attacks adapt classic web application vulnerabilities to AI systems. SQL injection through natural language, cross-site scripting via model output, server-side request forgery through URL manipulation, and indirect prompt injection via tool outputs. If a model generates unvalidated code or makes unsanitized requests, these attacks succeed.

Summary

4 attacks total: 4 single-turn.

Attacks

Example