SyncAI.news, a Varaisys broadcasting
Decision Hijacking: Prompt Injection Attacks on Jev's Typed Probabilistic Decisions
TW

Tiantong Wu, Wei Yang Bryan Lim

· 1 min read

ResearcharXiv cs.AI

Decision Hijacking: Prompt Injection Attacks on Jev's Typed Probabilistic Decisions

arXiv:2609.28613v1 Announce Type: cross Abstract: Most studies of prompt injection focus on generative agents, leaving their effects on models with schema-defined outputs unclear. We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target. Override markers reduce this influence, while claims of contextual relatedness have small effects. Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%. Exploratory analysis links these successes to small initial decision margins or greater attacker control over the observation. Together, these findings show that schema-defined outputs change but do not eliminate prompt-injection risk, highlighting the need to evaluate how untrusted content influences choices within the allowed action set.

Original source

This story was published by arXiv cs.AI and written by Tiantong Wu, Wei Yang Bryan Lim. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on arxiv.org

Similar News