Indirect Prompt Injection
間接プロンプトインジェクション
利用者が主たる指示として直接与えたのではなく、攻撃者や信頼されていない第三者が用意したWebページ、メール、ファイル、検索結果、取得文書、ツールの返り値などを通じて、プロンプトインジェクションの内容がモデルへ届く問題です。
ARC-V1-044
例
文書検索で取得した資料に回答とは無関係な操作を促す文が埋め込まれており、モデルがその文を利用者の指示と同じように扱った。
区別・注意
Prompt Injectionのうち、外部文書、検索結果、メール、ファイル、ツールの返り値など、外部または信頼されていないコンテンツを経由して指示が届く点が特徴です。単に外部文書に不正確な内容があるだけでは、間接プロンプトインジェクションとは限りません。RAGやツールを使う構成で起こり得ますが、RAGそのものやツールの汚染と同義ではありません。
Evidence
Evidenceを見る →
AI 100-2e2025 Adversarial Machine Learning
SRC-F07-001
- タイトル
- AI 100-2e2025 Adversarial Machine Learning
- 著者・組織
- Vassilev et al.; NIST
- 年
- 2025
- 種別
- Government official technical publication
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Prompt Injection, Direct/Indirect, Jailbreak boundary
- 範囲
- Cybersecurity taxonomy
- 限界
- Not the Catalog ontology itself
- アクセス・版
- Published official source
- URL / DOI
- 10.6028/NIST.AI.100-2e2025
Strengthening AI Agent Hijacking Evaluations
SRC-F07-002
- タイトル
- Strengthening AI Agent Hijacking Evaluations
- 著者・組織
- NIST CAISI
- 年
- 2025
- 種別
- Government primary evaluation / official blog
- 公開状態
- CURRENT
- 対応する用語・主張
- Indirect Prompt Injection, agent hijacking
- 範囲
- AgentDojo simulated environments
- 限界
- Simulation scope
- アクセス・版
- Official page referenced
- URL / DOI
- NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)
InjecAgent
SRC-F07-003
- タイトル
- InjecAgent
- 著者・組織
- Zhan et al.
- 年
- 2024
- 種別
- Peer-reviewed / Findings ACL 2024
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Indirect Prompt Injection vulnerability
- 範囲
- 1,054 cases, 30 agents
- 限界
- Benchmark conditions
- アクセス・版
- Published Findings ACL
- URL / DOI
- 10.18653/v1/2024.findings-acl.624
ATLAS
SRC-F07-008
- タイトル
- ATLAS
- 著者・組織
- MITRE
- 年
- 2026
- 種別
- Institutional security knowledge base / living
- 公開状態
- CURRENT
- 対応する用語・主張
- Prompt Injection vs Jailbreak; context and tool poisoning boundaries
- 範囲
- Security taxonomy
- 限界
- Not directly transferred into Catalog reliability ontology
- アクセス・版
- Living knowledge base; current in research input
- URL / DOI
- NOT_RECORDED_IN_RESEARCH_INPUT (official MITRE ATLAS page)
Agentic AI
SRC-F05-001
- タイトル
- Agentic AI
- 著者・組織
- NIST
- 年
- 2026
- 種別
- Government official web
- 公開状態
- CURRENT
- 対応する用語・主張
- AI Agent definition, autonomy, goal-driven interaction
- 範囲
- High-level official description
- 限界
- Not a universal implementation standard
- アクセス・版
- Official page referenced in research input
- URL / DOI
- NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)
AI Agent Standards Initiative
SRC-F05-002
- タイトル
- AI Agent Standards Initiative
- 著者・組織
- NIST
- 年
- 2026
- 種別
- Government initiative
- 公開状態
- CURRENT
- 対応する用語・主張
- AI Agent; reliability, interoperability, security concerns
- 範囲
- Initiative scope
- 限界
- Does not establish a single ontology
- アクセス・版
- Official page referenced in research input
- URL / DOI
- NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)
API-Bank: A Comprehensive Benchmark for Tool-Augmented LLMs
SRC-F05-003
- タイトル
- API-Bank: A Comprehensive Benchmark for Tool-Augmented LLMs
- 著者・組織
- Li et al.
- 年
- 2023
- 種別
- Peer-reviewed / EMNLP 2023
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Planning, Tool-selection, Tool-use
- 範囲
- 73 tools, 314 dialogues, 753 calls
- 限界
- 2023 model set
- アクセス・版
- Published EMNLP
- URL / DOI
- 10.18653/v1/2023.emnlp-main.187
LLM06:2025 Excessive Agency
SRC-F06-007
- タイトル
- LLM06:2025 Excessive Agency
- 著者・組織
- OWASP
- 年
- 2025
- 種別
- Institutional security guidance / living
- 公開状態
- CURRENT
- 対応する用語・主張
- Excessive Agency; permissions, functionality, autonomy, mitigation
- 範囲
- Security-framework terminology
- 限界
- Not ISO/JIS or universal terminology standard
- アクセス・版
- Living guidance; official page referenced
- URL / DOI
- NOT_RECORDED_IN_RESEARCH_INPUT (official OWASP page)
T1: A Tool-Oriented Conversational Dataset for Multi-Turn Agentic Planning
SRC-F05-004
- タイトル
- T1: A Tool-Oriented Conversational Dataset for Multi-Turn Agentic Planning
- 著者・組織
- Chakraborty et al.
- 年
- 2025
- 種別
- Peer-reviewed / NeurIPS 2025
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Planning, Memory, Tool-use
- 範囲
- Tool dependencies, multi-turn, cache/replanning
- 限界
- Centered on tool dependencies and multi-turn settings
- アクセス・版
- Published NeurIPS
- URL / DOI
- 10.52202/085713-3479
CostBench
SRC-F05-005
- タイトル
- CostBench
- 著者・組織
- Liu et al.
- 年
- 2026
- 種別
- Peer-reviewed / ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Planning Failure, replanning
- 範囲
- Travel/cost-optimal planning
- 限界
- Limited domain
- アクセス・版
- Published ACL
- URL / DOI
- 10.18653/v1/2026.acl-long.584
Goal Misgeneralization in Deep Reinforcement Learning
SRC-F06-003
- タイトル
- Goal Misgeneralization in Deep Reinforcement Learning
- 著者・組織
- Langosco et al.
- 年
- 2022
- 種別
- Peer-reviewed / ICML 2022
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Goal Misalignment boundary vs Goal Misgeneralization
- 範囲
- Deep RL evidence
- 限界
- Does not directly target LLM agents
- アクセス・版
- Published ICML/PMLR
- URL / DOI
- PMLR 162:12004–12019
Learning Human Objectives by Evaluating Hypothetical Behavior
SRC-F06-004
- タイトル
- Learning Human Objectives by Evaluating Hypothetical Behavior
- 著者・組織
- Reddy et al.
- 年
- 2020
- 種別
- Peer-reviewed / ICML 2020
- 公開状態
- PUBLISHED
- 対応する用語・主張
- User objective alignment, reward hacking correction
- 範囲
- RL/reward learning
- 限界
- RL context
- アクセス・版
- Published ICML/PMLR
- URL / DOI
- PMLR 119:8020–8029
EVOTOOL
SRC-F05-013
- タイトル
- EVOTOOL
- 著者・組織
- Yang et al.
- 年
- 2026
- 種別
- Peer-reviewed / ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Planner/Selector/Caller distinction, cross-module propagation
- 範囲
- Modular architecture
- 限界
- Not a universal architecture
- アクセス・版
- Published ACL
- URL / DOI
- 10.18653/v1/2026.acl-long.2016
ACEBench
SRC-F05-006
- タイトル
- ACEBench
- 著者・組織
- Chen et al.
- 年
- 2025
- 種別
- Peer-reviewed / Findings EMNLP 2025
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Tool-selection and Tool-use errors
- 範囲
- Benchmark task settings
- 限界
- Taxonomy dependent on benchmark design
- アクセス・版
- Published Findings EMNLP
- URL / DOI
- 10.18653/v1/2025.findings-emnlp.697
Robust Tool Use via Fission-GRPO
SRC-F05-010
- タイトル
- Robust Tool Use via Fission-GRPO
- 著者・組織
- Zhang et al.
- 年
- 2026
- 種別
- Peer-reviewed / ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Tool-use recovery, repeated invalid invocation
- 範囲
- Tested training method and models
- 限界
- Method-specific
- アクセス・版
- Published ACL
- URL / DOI
- 10.18653/v1/2026.acl-long.1880
SAMem: State-Aware Memory...
SRC-F05-008
- タイトル
- SAMem: State-Aware Memory...
- 著者・組織
- Wang et al.
- 年
- 2026
- 種別
- Peer-reviewed / Findings ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Memory retrieval/application failure
- 範囲
- Experiential memory and decision setting
- 限界
- Not a complete memory taxonomy
- アクセス・版
- Published Findings ACL
- URL / DOI
- 10.18653/v1/2026.findings-acl.722
HiAgent: Hierarchical Working Memory Management...
SRC-F05-009
- タイトル
- HiAgent: Hierarchical Working Memory Management...
- 著者・組織
- Hu et al.
- 年
- 2025
- 種別
- Peer-reviewed / ACL 2025
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Memory Failure mitigation
- 範囲
- Long-horizon tasks
- 限界
- Architecture-specific mitigation
- アクセス・版
- Published ACL
- URL / DOI
- 10.18653/v1/2025.acl-long.1575
BackdoorAgent
SRC-F05-014
- タイトル
- BackdoorAgent
- 著者・組織
- UNKNOWN
- 年
- 2026
- 種別
- Peer-reviewed / Findings ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Cross-stage propagation, memory/tool/planning
- 範囲
- Adversarial backdoor setting
- 限界
- Not unconditionally generalizable to natural failures
- アクセス・版
- Author or organization recorded as UNKNOWN
- URL / DOI
- 10.18653/v1/2026.findings-acl.791
When Agents Do Not Stop: Uncovering Infinite Agentic Loops in LLM Agents
SRC-F05-015
- タイトル
- When Agents Do Not Stop: Uncovering Infinite Agentic Loops in LLM Agents
- 著者・組織
- Hou et al.
- 年
- 2026
- 種別
- Primary preprint / arXiv
- 公開状態
- PREPRINT
- 対応する用語・主張
- Agent Non-termination
- 範囲
- Analysis of 6,549 repositories
- 限界
- Dedicated large-scale source is not peer-reviewed as of cutoff
- アクセス・版
- 2026 preprint; no published substitute used
- URL / DOI
- arXiv:2607.01641
FAMA
SRC-F05-011
- タイトル
- FAMA
- 著者・組織
- UNKNOWN
- 年
- 2026
- 種別
- Peer-reviewed / Findings ACL 2026
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Error accumulation, Cascading Failure
- 範囲
- Conversational/tool environments, especially open-source models
- 限界
- Scope is environment/model dependent
- アクセス・版
- Author or organization recorded as UNKNOWN
- URL / DOI
- 10.18653/v1/2026.findings-acl.1716
AgentPro
SRC-F05-012
- タイトル
- AgentPro
- 著者・組織
- Deng et al.
- 年
- 2025
- 種別
- Peer-reviewed / EMNLP 2025
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Error Propagation, process supervision
- 範囲
- Reasoning-chain propagation
- 限界
- Centered on reasoning chains
- アクセス・版
- Published EMNLP
- URL / DOI
- 10.18653/v1/2025.emnlp-main.506
Artificial Intelligence Risk Management Framework: Generative AI Profile
SRC-F06-002
- タイトル
- Artificial Intelligence Risk Management Framework: Generative AI Profile
- 著者・組織
- NIST
- 年
- 2024
- 種別
- Government official technical publication
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Overreliance, automation bias, oversight
- 範囲
- GenAI risk management
- 限界
- Contextual risk guidance
- アクセス・版
- Published official source
- URL / DOI
- 10.6028/NIST.AI.600-1
Does the Whole Exceed its Parts?
SRC-F06-005
- タイトル
- Does the Whole Exceed its Parts?
- 著者・組織
- Bansal et al.
- 年
- 2021
- 種別
- Peer-reviewed / CHI 2021
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Overreliance, appropriate reliance
- 範囲
- Predictive decision tasks
- 限界
- Interface/context differs from modern agents
- アクセス・版
- Published CHI
- URL / DOI
- 10.1145/3411764.3445717
Explainability does not mitigate the negative impact of incorrect AI advice...
SRC-F06-006
- タイトル
- Explainability does not mitigate the negative impact of incorrect AI advice...
- 著者・組織
- UNKNOWN
- 年
- 2024
- 種別
- Peer-reviewed / Scientific Reports
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Overreliance, explanation limitation
- 範囲
- Personnel-selection task
- 限界
- Task-specific
- アクセス・版
- Author or organization recorded as UNKNOWN
- URL / DOI
- 10.1038/s41598-024-60220-5
AI Risk Management Framework 1.0
SRC-F06-001
- タイトル
- AI Risk Management Framework 1.0
- 著者・組織
- NIST
- 年
- 2023
- 種別
- Government official technical publication
- 公開状態
- PUBLISHED
- 対応する用語・主張
- Human Oversight, roles, challenge/override context
- 範囲
- Broad risk framework
- 限界
- Not an experimental effect estimate
- アクセス・版
- Published official source
- URL / DOI
- 10.6028/NIST.AI.100-1