Transferable Direct Prompt Injection via Activation-Guided MCMC Sampling
Li, Minghui, Zhang, Hao, Zhang, Yechao, Wan, Wei, Hu, Shengshan, Xiaobing, pei, Wang, Jing
–arXiv.org Artificial Intelligence
Direct Prompt Injection (DPI) attacks pose a critical security threat to Large Language Models (LLMs) due to their low barrier of execution and high potential damage. To address the impracticality of existing white-box/gray-box methods and the poor transferability of black-box methods, we propose an activations-guided prompt injection attack framework. We first construct an Energy-based Model (EBM) using activations from a surrogate model to evaluate the quality of adversarial prompts. Guided by the trained EBM, we employ the token-level Markov Chain Monte Carlo (MCMC) sampling to adaptively optimize adversarial prompts, thereby enabling gradient-free black-box attacks. Experimental results demonstrate our superior cross-model transferability, achieving 49.6% attack success rate (ASR) across five mainstream LLMs and 34.6% improvement over human-crafted prompts, and maintaining 36.6% ASR on unseen task scenarios. Interpretability analysis reveals a correlation between activations and attack effectiveness, highlighting the critical role of semantic patterns in transferable vulnerability exploitation.
arXiv.org Artificial Intelligence
Sep-10-2025
- Country:
- Asia > Macao (0.04)
- Europe
- Eastern Europe (0.04)
- Ireland > Leinster
- County Dublin > Dublin (0.04)
- North America > United States
- Utah > Salt Lake County > Salt Lake City (0.04)
- Genre:
- Research Report > New Finding (1.00)
- Industry:
- Government (1.00)
- Health & Medicine > Consumer Health (0.94)
- Information Technology > Security & Privacy (1.00)
- Technology: