{
  "id": "prompt-injection",
  "code": "PTL-0087",
  "term": "Prompt Injection",
  "aliases": [
    "goal hijacking",
    "instruction injection"
  ],
  "category": "security",
  "definition": "Prompt injection is an attack in which text supplied to a language model, by a user or through data the model processes, contains instructions that override or subvert the instructions of the application's developer.",
  "description": "The name was coined in 2022 by analogy with SQL injection, because models cannot reliably separate trusted instructions from untrusted data that share the same context. It is the most prominent security risk for applications built on language models, especially agents with tool access.",
  "example": null,
  "broader": [],
  "narrower": [
    "indirect-prompt-injection",
    "prompt-leaking"
  ],
  "related": [
    "jailbreak",
    "instruction-hierarchy",
    "spotlighting"
  ],
  "introduced": 2022,
  "sources": [
    {
      "title": "Prompt injection attacks against GPT-3",
      "authors": "Willison",
      "year": 2022,
      "url": "https://simonwillison.net/2022/Sep/12/prompt-injection/"
    },
    {
      "title": "Ignore Previous Prompt: Attack Techniques For Language Models",
      "authors": "Perez & Ribeiro",
      "year": 2022,
      "url": "https://arxiv.org/abs/2211.09527"
    }
  ],
  "url": "https://protologue.com/t/prompt-injection/",
  "citation": "Protologue. (2026). Prompt Injection. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0087). https://protologue.com/t/prompt-injection/"
}