← Catalogへ戻る

Indirect Prompt Injection

間接プロンプトインジェクション

利用者が主たる指示として直接与えたのではなく、攻撃者や信頼されていない第三者が用意したWebページ、メール、ファイル、検索結果、取得文書、ツールの返り値などを通じて、プロンプトインジェクションの内容がモデルへ届く問題です。

ARC-V1-044

文書検索で取得した資料に回答とは無関係な操作を促す文が埋め込まれており、モデルがその文を利用者の指示と同じように扱った。

区別・注意

Prompt Injectionのうち、外部文書、検索結果、メール、ファイル、ツールの返り値など、外部または信頼されていないコンテンツを経由して指示が届く点が特徴です。単に外部文書に不正確な内容があるだけでは、間接プロンプトインジェクションとは限りません。RAGやツールを使う構成で起こり得ますが、RAGそのものやツールの汚染と同義ではありません。

Evidence

Evidenceを見る →

AI 100-2e2025 Adversarial Machine Learning

SRC-F07-001

タイトル
AI 100-2e2025 Adversarial Machine Learning
著者・組織
Vassilev et al.; NIST
2025
種別
Government official technical publication
公開状態
PUBLISHED
対応する用語・主張
Prompt Injection, Direct/Indirect, Jailbreak boundary
範囲
Cybersecurity taxonomy
限界
Not the Catalog ontology itself
アクセス・版
Published official source
URL / DOI
10.6028/NIST.AI.100-2e2025

Strengthening AI Agent Hijacking Evaluations

SRC-F07-002

タイトル
Strengthening AI Agent Hijacking Evaluations
著者・組織
NIST CAISI
2025
種別
Government primary evaluation / official blog
公開状態
CURRENT
対応する用語・主張
Indirect Prompt Injection, agent hijacking
範囲
AgentDojo simulated environments
限界
Simulation scope
アクセス・版
Official page referenced
URL / DOI
NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)

InjecAgent

SRC-F07-003

タイトル
InjecAgent
著者・組織
Zhan et al.
2024
種別
Peer-reviewed / Findings ACL 2024
公開状態
PUBLISHED
対応する用語・主張
Indirect Prompt Injection vulnerability
範囲
1,054 cases, 30 agents
限界
Benchmark conditions
アクセス・版
Published Findings ACL
URL / DOI
10.18653/v1/2024.findings-acl.624

ATLAS

SRC-F07-008

タイトル
ATLAS
著者・組織
MITRE
2026
種別
Institutional security knowledge base / living
公開状態
CURRENT
対応する用語・主張
Prompt Injection vs Jailbreak; context and tool poisoning boundaries
範囲
Security taxonomy
限界
Not directly transferred into Catalog reliability ontology
アクセス・版
Living knowledge base; current in research input
URL / DOI
NOT_RECORDED_IN_RESEARCH_INPUT (official MITRE ATLAS page)

Agentic AI

SRC-F05-001

タイトル
Agentic AI
著者・組織
NIST
2026
種別
Government official web
公開状態
CURRENT
対応する用語・主張
AI Agent definition, autonomy, goal-driven interaction
範囲
High-level official description
限界
Not a universal implementation standard
アクセス・版
Official page referenced in research input
URL / DOI
NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)

AI Agent Standards Initiative

SRC-F05-002

タイトル
AI Agent Standards Initiative
著者・組織
NIST
2026
種別
Government initiative
公開状態
CURRENT
対応する用語・主張
AI Agent; reliability, interoperability, security concerns
範囲
Initiative scope
限界
Does not establish a single ontology
アクセス・版
Official page referenced in research input
URL / DOI
NOT_RECORDED_IN_RESEARCH_INPUT (official NIST page)

API-Bank: A Comprehensive Benchmark for Tool-Augmented LLMs

SRC-F05-003

タイトル
API-Bank: A Comprehensive Benchmark for Tool-Augmented LLMs
著者・組織
Li et al.
2023
種別
Peer-reviewed / EMNLP 2023
公開状態
PUBLISHED
対応する用語・主張
Planning, Tool-selection, Tool-use
範囲
73 tools, 314 dialogues, 753 calls
限界
2023 model set
アクセス・版
Published EMNLP
URL / DOI
10.18653/v1/2023.emnlp-main.187

LLM06:2025 Excessive Agency

SRC-F06-007

タイトル
LLM06:2025 Excessive Agency
著者・組織
OWASP
2025
種別
Institutional security guidance / living
公開状態
CURRENT
対応する用語・主張
Excessive Agency; permissions, functionality, autonomy, mitigation
範囲
Security-framework terminology
限界
Not ISO/JIS or universal terminology standard
アクセス・版
Living guidance; official page referenced
URL / DOI
NOT_RECORDED_IN_RESEARCH_INPUT (official OWASP page)

T1: A Tool-Oriented Conversational Dataset for Multi-Turn Agentic Planning

SRC-F05-004

タイトル
T1: A Tool-Oriented Conversational Dataset for Multi-Turn Agentic Planning
著者・組織
Chakraborty et al.
2025
種別
Peer-reviewed / NeurIPS 2025
公開状態
PUBLISHED
対応する用語・主張
Planning, Memory, Tool-use
範囲
Tool dependencies, multi-turn, cache/replanning
限界
Centered on tool dependencies and multi-turn settings
アクセス・版
Published NeurIPS
URL / DOI
10.52202/085713-3479

CostBench

SRC-F05-005

タイトル
CostBench
著者・組織
Liu et al.
2026
種別
Peer-reviewed / ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Planning Failure, replanning
範囲
Travel/cost-optimal planning
限界
Limited domain
アクセス・版
Published ACL
URL / DOI
10.18653/v1/2026.acl-long.584

Goal Misgeneralization in Deep Reinforcement Learning

SRC-F06-003

タイトル
Goal Misgeneralization in Deep Reinforcement Learning
著者・組織
Langosco et al.
2022
種別
Peer-reviewed / ICML 2022
公開状態
PUBLISHED
対応する用語・主張
Goal Misalignment boundary vs Goal Misgeneralization
範囲
Deep RL evidence
限界
Does not directly target LLM agents
アクセス・版
Published ICML/PMLR
URL / DOI
PMLR 162:12004–12019

Learning Human Objectives by Evaluating Hypothetical Behavior

SRC-F06-004

タイトル
Learning Human Objectives by Evaluating Hypothetical Behavior
著者・組織
Reddy et al.
2020
種別
Peer-reviewed / ICML 2020
公開状態
PUBLISHED
対応する用語・主張
User objective alignment, reward hacking correction
範囲
RL/reward learning
限界
RL context
アクセス・版
Published ICML/PMLR
URL / DOI
PMLR 119:8020–8029

EVOTOOL

SRC-F05-013

タイトル
EVOTOOL
著者・組織
Yang et al.
2026
種別
Peer-reviewed / ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Planner/Selector/Caller distinction, cross-module propagation
範囲
Modular architecture
限界
Not a universal architecture
アクセス・版
Published ACL
URL / DOI
10.18653/v1/2026.acl-long.2016

ACEBench

SRC-F05-006

タイトル
ACEBench
著者・組織
Chen et al.
2025
種別
Peer-reviewed / Findings EMNLP 2025
公開状態
PUBLISHED
対応する用語・主張
Tool-selection and Tool-use errors
範囲
Benchmark task settings
限界
Taxonomy dependent on benchmark design
アクセス・版
Published Findings EMNLP
URL / DOI
10.18653/v1/2025.findings-emnlp.697

Robust Tool Use via Fission-GRPO

SRC-F05-010

タイトル
Robust Tool Use via Fission-GRPO
著者・組織
Zhang et al.
2026
種別
Peer-reviewed / ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Tool-use recovery, repeated invalid invocation
範囲
Tested training method and models
限界
Method-specific
アクセス・版
Published ACL
URL / DOI
10.18653/v1/2026.acl-long.1880

SAMem: State-Aware Memory...

SRC-F05-008

タイトル
SAMem: State-Aware Memory...
著者・組織
Wang et al.
2026
種別
Peer-reviewed / Findings ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Memory retrieval/application failure
範囲
Experiential memory and decision setting
限界
Not a complete memory taxonomy
アクセス・版
Published Findings ACL
URL / DOI
10.18653/v1/2026.findings-acl.722

HiAgent: Hierarchical Working Memory Management...

SRC-F05-009

タイトル
HiAgent: Hierarchical Working Memory Management...
著者・組織
Hu et al.
2025
種別
Peer-reviewed / ACL 2025
公開状態
PUBLISHED
対応する用語・主張
Memory Failure mitigation
範囲
Long-horizon tasks
限界
Architecture-specific mitigation
アクセス・版
Published ACL
URL / DOI
10.18653/v1/2025.acl-long.1575

BackdoorAgent

SRC-F05-014

タイトル
BackdoorAgent
著者・組織
UNKNOWN
2026
種別
Peer-reviewed / Findings ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Cross-stage propagation, memory/tool/planning
範囲
Adversarial backdoor setting
限界
Not unconditionally generalizable to natural failures
アクセス・版
Author or organization recorded as UNKNOWN
URL / DOI
10.18653/v1/2026.findings-acl.791

When Agents Do Not Stop: Uncovering Infinite Agentic Loops in LLM Agents

SRC-F05-015

タイトル
When Agents Do Not Stop: Uncovering Infinite Agentic Loops in LLM Agents
著者・組織
Hou et al.
2026
種別
Primary preprint / arXiv
公開状態
PREPRINT
対応する用語・主張
Agent Non-termination
範囲
Analysis of 6,549 repositories
限界
Dedicated large-scale source is not peer-reviewed as of cutoff
アクセス・版
2026 preprint; no published substitute used
URL / DOI
arXiv:2607.01641

FAMA

SRC-F05-011

タイトル
FAMA
著者・組織
UNKNOWN
2026
種別
Peer-reviewed / Findings ACL 2026
公開状態
PUBLISHED
対応する用語・主張
Error accumulation, Cascading Failure
範囲
Conversational/tool environments, especially open-source models
限界
Scope is environment/model dependent
アクセス・版
Author or organization recorded as UNKNOWN
URL / DOI
10.18653/v1/2026.findings-acl.1716

AgentPro

SRC-F05-012

タイトル
AgentPro
著者・組織
Deng et al.
2025
種別
Peer-reviewed / EMNLP 2025
公開状態
PUBLISHED
対応する用語・主張
Error Propagation, process supervision
範囲
Reasoning-chain propagation
限界
Centered on reasoning chains
アクセス・版
Published EMNLP
URL / DOI
10.18653/v1/2025.emnlp-main.506

Artificial Intelligence Risk Management Framework: Generative AI Profile

SRC-F06-002

タイトル
Artificial Intelligence Risk Management Framework: Generative AI Profile
著者・組織
NIST
2024
種別
Government official technical publication
公開状態
PUBLISHED
対応する用語・主張
Overreliance, automation bias, oversight
範囲
GenAI risk management
限界
Contextual risk guidance
アクセス・版
Published official source
URL / DOI
10.6028/NIST.AI.600-1

Does the Whole Exceed its Parts?

SRC-F06-005

タイトル
Does the Whole Exceed its Parts?
著者・組織
Bansal et al.
2021
種別
Peer-reviewed / CHI 2021
公開状態
PUBLISHED
対応する用語・主張
Overreliance, appropriate reliance
範囲
Predictive decision tasks
限界
Interface/context differs from modern agents
アクセス・版
Published CHI
URL / DOI
10.1145/3411764.3445717

Explainability does not mitigate the negative impact of incorrect AI advice...

SRC-F06-006

タイトル
Explainability does not mitigate the negative impact of incorrect AI advice...
著者・組織
UNKNOWN
2024
種別
Peer-reviewed / Scientific Reports
公開状態
PUBLISHED
対応する用語・主張
Overreliance, explanation limitation
範囲
Personnel-selection task
限界
Task-specific
アクセス・版
Author or organization recorded as UNKNOWN
URL / DOI
10.1038/s41598-024-60220-5

AI Risk Management Framework 1.0

SRC-F06-001

タイトル
AI Risk Management Framework 1.0
著者・組織
NIST
2023
種別
Government official technical publication
公開状態
PUBLISHED
対応する用語・主張
Human Oversight, roles, challenge/override context
範囲
Broad risk framework
限界
Not an experimental effect estimate
アクセス・版
Published official source
URL / DOI
10.6028/NIST.AI.100-1