Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Published in AISec'23 workshop (co-located with CCS. Oral presentation. Best Paper Award), 2009