Definition · foundations
prompt injection
prompt injection is an attack that puts commands in model input to override the task or rules. You can spot prompt injection in practice when the record shows what the system observes, what choice it makes, and what changes next, without asking the reader to guess or trust a slogan.
157 definitions656 sourced recordsNamed source: ACL Anthology
Why does prompt injection matter?
Injected commands compete with the real task and can redirect tools, data, or output unless trust boundaries are enforced. For prompt injection, start with three checks: What can the system observe? What choice can it make? What changes after it acts? The answers should point to visible evidence, not a promise.
What does prompt injection look like?
A pasted document tells the model to ignore review rules and approve every claim. This example makes prompt injection visible by naming the actor, the action, and the result in practice. It is an illustration for readers, not a claim that every product behaves this way.
What is prompt injection easy to confuse with?
Prompt injection is the broad attack. Indirect prompt injection hides the commands inside retrieved data. The closest entries here are plan-and-execute, provisional claim, indirect prompt injection. Compare their definitions with prompt injection before using the names as if they mean the same thing. That comparison keeps prompt injection separate from nearby ideas without pretending the boundary is always perfect.
How certain is this definition?
This definition is provisional. ACL Anthology supports the version you see today, but a better or more direct source may change it. Open the cited page and check its date before you use this entry to choose a product, write a policy, set a safety control, or design a system.
Who introduced the term prompt injection?
We have not verified who first introduced prompt injection. The source supports a useful definition, but it may not be the earliest use. Until a dated primary record settles the question, we leave the origin open. A popular article or product page is not enough to name the person who coined a term.
What should you understand before prompt injection?
Read artificial intelligence (AI) first when prompt injection depends on a more basic idea or mechanism. The link gives you a useful route through the glossary. It does not mean every author teaches the subject in this order, so follow the source when the sequence matters.
What should this term help you answer?
Use prompt injection to ask what an agent can observe, decide, change, remember, or hand off. The questions below turn the definition into a practical check. They are prompts for your own work, not claims made by the source, so change them to fit the system you are examining.
- What can the system observe?
- What choice can it make?
- What changes after it acts?
Which source supports this definition of prompt injection?
ACL Anthology supports this working definition of prompt injection. We checked the link on 2026-07-12. Open the original record for its context, methods, limits, and publication details. The short explanation here is a guide to prompt injection; the linked source remains the evidence to inspect when the wording or boundary matters.
source foundprompt injectionChecked 2026-07-12→