# Prompt Injection

> Prompt injection is an attack in which text supplied to a language model, by a user or through data the model processes, contains instructions that override or subvert the instructions of the application's developer.

- Identifier: PTL-0087
- Category: Security & Adversarial Prompting
- Canonical URL: https://protologue.com/t/prompt-injection/
- Also known as: goal hijacking, instruction injection
- Introduced: 2022

## Description

The name was coined in 2022 by analogy with SQL injection, because models cannot reliably separate trusted instructions from untrusted data that share the same context. It is the most prominent security risk for applications built on language models, especially agents with tool access.

## Narrower terms

- [Indirect Prompt Injection](https://protologue.com/t/indirect-prompt-injection/)
- [Prompt Leaking](https://protologue.com/t/prompt-leaking/)

## Related terms

- [Jailbreak](https://protologue.com/t/jailbreak/)
- [Instruction Hierarchy](https://protologue.com/t/instruction-hierarchy/)
- [Spotlighting](https://protologue.com/t/spotlighting/)

## Sources

- Willison (2022). Prompt injection attacks against GPT-3. https://simonwillison.net/2022/Sep/12/prompt-injection/
- Perez & Ribeiro (2022). Ignore Previous Prompt: Attack Techniques For Language Models. https://arxiv.org/abs/2211.09527

## Cite this entry

Protologue. (2026). Prompt Injection. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0087). https://protologue.com/t/prompt-injection/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
