about
Prompt Injection 2.0: Hybrid AI Threats – Paper and Open Source Testing Toolkit (arxiv.org)
3 points by jmchugh9 on Jul 23, 2025 | hide | past | pdf | 1 comment on HN

In plain words: The study examines how prompt injections—fake commands that make AI ignore its instructions—combine with web tricks like cross-site scripting to slip past firewalls, filters, and tokens. Those usual defenses fail, so it proposes isolating prompts, limiting privileges, and checking actions while running.

Abstract · Prompt Injection 2.0: Hybrid AI Threats

Prompt injection attacks, where malicious input is designed to manipulate AI systems into ignoring their original instructions and following unauthorized commands instead, were first discovered by Preamble, Inc. in May 2022 and responsibly disclosed to OpenAI. Over the last three years, these attacks have continued to pose a critical security threat to LLM-integrated systems. The emergence of agentic AI systems, where LLMs autonomously perform multistep tasks through tools and coordination with other agents, has fundamentally transformed the threat landscape. Modern prompt injection attacks can now combine with traditional cybersecurity exploits to create hybrid threats that systematically evade traditional security controls. This paper presents a comprehensive analysis of Prompt Injection 2.0, examining how prompt injections integrate with Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and other web security vulnerabilities to bypass traditional security measures. We build upon Preamble's foundational research and mitigation technologies, evaluating them against contemporary threats, including AI worms, multi-agent infections, and hybrid cyber-AI attacks. Our analysis incorporates recent benchmarks that demonstrate how traditional web application firewalls, XSS filters, and CSRF tokens fail against AI-enhanced attacks. We also present architectural solutions that combine prompt isolation, runtime security, and privilege separation with novel threat detection capabilities.

Jeremy McHugh, Kristina Šekrst, Jon Cefalu
arXiv:2507.13169 · cs.CR, cs.AI · submitted Jul 17, 2025
abstract · pdf · html

add comment on HN

We published "Prompt Injection 2.0: Hybrid AI Threats" on arXiv and released our Prompt Injector tool as open source.

Key findings from the research: - Modern prompt injection attacks now combine with traditional web vulnerabilities (XSS, CSRF) to create hybrid threats - Traditional security controls (WAFs, input sanitization) fail against AI-enhanced attacks - Agentic AI systems create new attack surfaces - New taxonomy for prompt injections

Open Source Tool: - Prompt Injector v1 now available under Apache 2.0 license - Desktop app for testing AI systems against prompt injection attacks - Supports OpenAI, Anthropic, Google, Grok, and Ollama models - 150+ payloads - GitHub: https://github.com/preambleai/prompt-injector

Background: We first discovered prompt injection vulnerabilities in GPT-3 back in May 2022 and responsibly disclosed to OpenAI. This new research shows how the threat landscape has evolved with agentic AI systems.