{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:14:56Z","timestamp":1778109296493,"version":"3.51.4"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160911","type":"print"},{"value":"9783032160928","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16092-8_24","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:01:34Z","timestamp":1778108494000},"page":"436-455","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Methodology for\u00a0Systematic Security Testing of\u00a0LLM-Based Applications"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7730-9219","authenticated-orcid":false,"given":"Dawid","family":"Nastaj","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8509-4127","authenticated-orcid":false,"given":"Wojciech","family":"Mazurczyk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"24_CR1","unstructured":"Uszkoreit, J.: Transformer: A Novel Neural Network Architecture for Language Understanding. https:\/\/blog.research.google\/2017\/08\/transformer-novel-neural-network.html. Accessed 25 June 2025"},{"key":"24_CR2","unstructured":"OWASP: OWASP TOP 10 LLM. https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/. Accessed 25 July 2025"},{"key":"24_CR3","unstructured":"OWASP: OWASP LLM Security Verification Standard. https:\/\/owasp.org\/www-project-llm-verification-standard\/. Accessed 19 July 2025"},{"key":"24_CR4","unstructured":"WDTA: Large Language Model Security Testing Method. https:\/\/wdtacademy.org\/publications\/LargeLanguageModelSecurityTestingMethod. Accessed 19 Aug 2025"},{"key":"24_CR5","unstructured":"MITRE: MITRE ATLAS. https:\/\/atlas.mitre.org\/. Accessed 25 July 2025"},{"key":"24_CR6","unstructured":"ProtectAI: ProtectAI About Us. https:\/\/protectai.com\/about. Accessed 25 July 2025"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"Liu, T., Deng, Z., Meng, G., Li, Y., Chen, K.: Demystifying RCE vulnerabilities in LLM-integrated apps. In: Black Hat Asia 2024 Briefings (2024)","DOI":"10.1145\/3658644.3690338"},{"key":"24_CR8","unstructured":"MITRE: CVE Details. https:\/\/www.cvedetails.com\/. Accessed 25 July 2025"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Greshake, K., Abdelnabi, S., Mishra, S., Endres, C., Holz, T., Fritz, M.: Not what you\u2019ve signed up for: compromising real-world LLM-integrated applications with indirect prompt injection. In: Proc. of the 16th ACM Workshop on Artificial Intelligence and Security (AISec 2023), pp. 79\u201390 (2023)","DOI":"10.1145\/3605764.3623985"},{"key":"24_CR10","unstructured":"Deng, Y., Zhang, W., Pan, S.J., Bing, L.: Multilingual jailbreak challenges in large language models. In: The 12th International Conference on Learning Representations (ICLR 2024). OpenReview.net (2024)"},{"key":"24_CR11","unstructured":"Perez, F., Ribeiro, I.: Ignore previous prompt: attack techniques for language models. In: NeurIPS ML Safety Workshop (2022)"},{"key":"24_CR12","unstructured":"Sprocket Security: Large Language Model (LLM) Security Testing: Types, Techniques, and Methodology (2024). https:\/\/www.sprocketsecurity.com\/blog\/large-language-model-llm-security-testing-types-techniques-and-methodology. Accessed 19 Aug 2025"},{"key":"24_CR13","unstructured":"Aardwolf Security: LLM Security Testing and Risks (2023). https:\/\/www.sprocketsecurity.com\/blog\/large-language-model-llm-security-testing-types-techniques-and-methodology. Accessed 19 Aug 2025"},{"key":"24_CR14","unstructured":"PortSwigger: Laboratoria PortSwigger. https:\/\/portswigger.net\/web-security\/llm-attacks. Accessed 25 July 2025"},{"key":"24_CR15","unstructured":"@harishsg993010: DamnVulnerableLLMProject. https:\/\/github.com\/harishsg993010\/DamnVulnerableLLMProject. Accessed 25 July 2025"},{"key":"24_CR16","unstructured":"@HadessCS: Delta. https:\/\/github.com\/HadessCS\/Delta. Accessed 25 July 2025"},{"key":"24_CR17","unstructured":"svenmorgenrothio: Prompt Injection Playground. https:\/\/github.com\/svenmorgenrothio\/Prompt-Injection-Playground. Accessed 25 July 2025"},{"key":"24_CR18","unstructured":"WithSecureLabs: Damn Vulnerable LLM Agent. https:\/\/github.com\/WithSecureLabs\/damn-vulnerable-llm-agent. Accessed 25 July 2025"},{"key":"24_CR19","unstructured":"LakeraAI: Lakera Gandalf. https:\/\/gandalf.lakera.ai. Accessed 25 July 2025"},{"key":"24_CR20","unstructured":"LakeraAI: Tensor Trust. https:\/\/tensortrust.ai. Accessed 25 July 2025"},{"key":"24_CR21","unstructured":"kinugawamasato: Cross-Site Scripting. Twitter (2024). https:\/\/twitter.com\/kinugawamasato\/status\/1649080543840210945. Accessed 25 July 2025"},{"key":"24_CR22","unstructured":"hwchase17: Model Denial of Service. Twitter (2024). https:\/\/twitter.com\/hwchase17\/status\/1608467493877579777. Accessed 25 July 2025"},{"key":"24_CR23","unstructured":"coolaj86: Do Anything Now Instruction. Gist (2023). https:\/\/gist.github.com\/coolaj86\/6f4f7b30129b0251f61fa7baaa881516. Accessed 25 July 2025"},{"key":"24_CR24","unstructured":"@mik0w: LLM causing self-XSS. Hackstery (2023). https:\/\/hackstery.com\/2023\/07\/10\/llm-causing-self-xss\/. Accessed 25 July 2025"},{"key":"24_CR25","unstructured":"OWASP: OWASP Application Security Verification Standard. https:\/\/owasp.org\/www-project-application-security-verification-standard\/. Accessed 25 July 2025"},{"key":"24_CR26","unstructured":"OWASP: OWASP Web Security Testing Guide. https:\/\/owasp.org\/www-project-web-security-testing-guide\/. Accessed 25 July 2025"},{"key":"24_CR27","unstructured":"Mintplex-Labs: AnythingLLM. https:\/\/github.com\/Mintplex-Labs\/anything-llm. Accessed 25 July 2025"},{"key":"24_CR28","unstructured":"GaiZhenbiao: ChuanhuChatGPT. https:\/\/github.com\/GaiZhenbiao\/ChuanhuChat\/GPT. Accessed 25 July 2025"},{"key":"24_CR29","unstructured":"ParisNeo: lollms-webui. https:\/\/github.com\/ParisNeo\/lollms-webui. Accessed 25 July 2025"},{"key":"24_CR30","unstructured":"BentoML: OpenLLM. https:\/\/github.com\/bentoml\/OpenLLM. Accessed 25 July 2025"},{"key":"24_CR31","unstructured":"Significant-Gravitas: AutoGPT. https:\/\/github.com\/Significant-Gravitas\/AutoGPT. Accessed 25 July 2025"},{"key":"24_CR32","unstructured":"LangchainAI: langchain. https:\/\/github.com\/langchain-ai\/langchain. Accessed 25 July 2025"},{"key":"24_CR33","unstructured":"imartinez: PrivateGPT. https:\/\/github.com\/imartinez\/privateGPT. Accessed 25 July 2025"},{"key":"24_CR34","unstructured":"mlc-ai: web-llm. https:\/\/github.com\/mlc-ai\/web-llm. Accessed 25 July 2025"},{"key":"24_CR35","unstructured":"Microsoft: Autogen. https:\/\/github.com\/microsoft\/autogen. Accessed 25 July 2025"},{"key":"24_CR36","unstructured":"LobeHub: LobeChat. https:\/\/github.com\/lobehub\/lobe-chat. Accessed 25 July 2025"},{"key":"24_CR37","unstructured":"NIAC: CVSS. https:\/\/www.first.org\/cvss\/v1\/cvss-dhs-12-02-04.pdf. Accessed 25 July 2025"},{"key":"24_CR38","unstructured":"StitionAI: Devika. https:\/\/github.com\/stitionai\/devika. Accessed 25 July 2025"},{"key":"24_CR39","unstructured":"Open-WebUI: Open-WebUI. https:\/\/github.com\/open-webui\/open-webui. Accessed 25 July 2025"},{"key":"24_CR40","unstructured":"DanswerAI: Danswer. https:\/\/github.com\/danswer-ai\/danswer. Accessed 25 July 2025"},{"key":"24_CR41","unstructured":"netease-youdao: QAnything. https:\/\/github.com\/netease-youdao\/QAnything. Accessed 25 July 2025"},{"key":"24_CR42","unstructured":"Aqua Security: Why Is It Important to Secure Large Language Models (LLM)? https:\/\/www.aquasec.com\/cloud-native-academy\/vulnerability-management\/llm-security\/. Accessed 25 July 2025"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16092-8_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:01:45Z","timestamp":1778108505000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16092-8_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160911","9783032160928"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16092-8_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}