{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T23:55:48Z","timestamp":1783814148665,"version":"3.55.0"},"reference-count":39,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,5,15]],"date-time":"2024-05-15T00:00:00Z","timestamp":1715731200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,5,15]],"date-time":"2024-05-15T00:00:00Z","timestamp":1715731200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,5,15]]},"DOI":"10.1109\/ichms59971.2024.10555871","type":"proceedings-article","created":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T17:22:35Z","timestamp":1718817755000},"page":"1-6","source":"Crossref","is-referenced-by-count":22,"title":["Strengthening LLM Trust Boundaries: A Survey of Prompt Injection Attacks Surender Suresh Kumar Dr. M.L. Cummings Dr. Alexander Stimpson"],"prefix":"10.1109","author":[{"given":"Surender Suresh","family":"Kumar","sequence":"first","affiliation":[{"name":"George Mason University,Department of Electrical and Computer Engineering,Fairfax,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M.L.","family":"Cummings","sequence":"additional","affiliation":[{"name":"George Mason University,Department of Electrical and Computer Engineering,Fairfax,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alexander","family":"Stimpson","sequence":"additional","affiliation":[{"name":"George Mason University,Department of Mechanical Engineering,Fairfax,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"BERT: Pretraining of Deep Bidirec onal Transformers for Language Understanding","author":"Devlin","year":"2019","journal-title":"arXiv"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1907.11692"},{"key":"ref3","article-title":"LLaMA: Open and Efficient Founda on Language Models","author":"Touvron","year":"2023","journal-title":"arXiv"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.507"},{"key":"ref5","article-title":"Mastering Diverse Domains through World Models","author":"Hafner","year":"2023","journal-title":"arXiv"},{"key":"ref6","article-title":"Whats the Magic Word? A Control Theory of LLM Promp ng","author":"Bhargava","year":"2023","journal-title":"arXiv"},{"key":"ref7","article-title":"Deep Reinforcement Learning from Human Preferences","volume-title":"Advances in Neural Informa on Processing Systems, Curran Associates, Inc., 2017. Accessed:","author":"Chris ano"},{"key":"ref8","article-title":"Understanding the Effects of RLHF on LLM Generalisa on and Diversity","author":"Kirk","year":"2023","journal-title":"arXiv"},{"key":"ref9","article-title":"llama_tokeniza on_fast.py","author":"Mishra","year":"2024","journal-title":"GitHub. Accessed:"},{"key":"ref10","article-title":"Scalable Extrac on of Training Data from (Produc on) Language Models","author":"Nasr","year":"2023","journal-title":"arXiv"},{"key":"ref11","article-title":"Ignore Previous Prompt: A ack Techniques For Language Models","author":"Perez","year":"2022","journal-title":"arXiv"},{"key":"ref12","article-title":"Not what youve signed up for: Compromising Real-World LLM-Integrated Applica ons with Indirect Prompt Injec on","author":"Greshake","year":"2023","journal-title":"arXiv"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.410"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"ref15","volume-title":"LLaMA","year":"2024"},{"key":"ref16","article-title":"Universal and Transferable Adversarial A acks on Aligned Language Models","author":"Zou","year":"2023","journal-title":"arXiv"},{"key":"ref17","article-title":"Open Sesame! Universal Black Box Jailbreaking of Large Language Models","author":"Lapid","year":"2023","journal-title":"arXiv"},{"key":"ref18","article-title":"ktoken","author":"Kikpatrick","year":"2023","journal-title":"OpenAI"},{"key":"ref19","article-title":"Claude Tokenizer","author":"Hirsch","year":"2023"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.290"},{"key":"ref21","article-title":"ChatGPT_DAN","author":"Lee","year":"2023"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.6028\/nist.ai.100-2e2023"},{"key":"ref23","article-title":"A en on Is All You Need","author":"Vaswani","year":"2023","journal-title":"arXiv"},{"key":"ref24","article-title":"Evalua ng the Suscep bility of Pre-Trained Language Models via Handcra ed Adversarial Examples","author":"Branch","year":"2022","journal-title":"arXiv"},{"key":"ref25","article-title":"Jailbroken: How Does LLM Safety Training Fail?","author":"Wei","year":"2023","journal-title":"arXiv"},{"key":"ref26","volume-title":"Collec on of LLM Prompt Format for Roleplaying","year":"2023"},{"key":"ref27","article-title":"Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned","author":"Ganguli","year":"2022","journal-title":"arXiv"},{"key":"ref28","article-title":"Grandma Exploit","year":"2023","journal-title":"r\/ChatGPT"},{"key":"ref29","article-title":"LLM Hacking: Prompt Injec on Techniques","author":"Stubbs","year":"2023","journal-title":"Medium. Accessed:"},{"key":"ref30","article-title":"Privacy Side Channels in Machine Learning Systems","author":"Debenede","year":"2023","journal-title":"arXiv"},{"key":"ref31","article-title":"Follow Riley Goodside","author":"Goodside","year":"2024","journal-title":"ChatGPT. Accessed:"},{"key":"ref32","author":"Wu","year":"2023","journal-title":"Defending ChatGPT against Jailbreak A ack via SelfReminder"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1155\/2023\/8691095"},{"key":"ref34","article-title":"Inject My PDF: Prompt Injec on for your Resume","author":"Greshake","year":"2023","journal-title":"Accessed:"},{"key":"ref35","article-title":"Prompt injec on: Whats the worst that can happen?","author":"Willison","year":"2023","journal-title":"Accessed:"},{"key":"ref36","article-title":"Fondu.ai-Data exfiltra on via Indirect Prompt Injec on in ChatGPT","year":"2023","journal-title":"Fondu.ai"},{"key":"ref37","article-title":"Prompt Injec on a ack against LLM-integrated Applica ons","author":"Liu","year":"2023","journal-title":"arXiv"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-long.556"},{"key":"ref39","article-title":"Explaining and Harnessing Adversarial Examples","author":"Goodfellow","year":"2015","journal-title":"arXiv"}],"event":{"name":"2024 IEEE 4th International Conference on Human-Machine Systems (ICHMS)","location":"Toronto, ON, Canada","start":{"date-parts":[[2024,5,15]]},"end":{"date-parts":[[2024,5,17]]}},"container-title":["2024 IEEE 4th International Conference on Human-Machine Systems (ICHMS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10555565\/10555582\/10555871.pdf?arnumber=10555871","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,25]],"date-time":"2024-06-25T19:15:07Z","timestamp":1719342907000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10555871\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,15]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/ichms59971.2024.10555871","relation":{},"subject":[],"published":{"date-parts":[[2024,5,15]]}}}