Nachweis
Quellenverzeichnis
Alle Sachaussagen dieses Portals stützen sich auf verlinkte Primärquellen. Dieses Verzeichnis führt sie an einer Stelle zusammen — sortiert nach Bereich, mit der Zahl der Seiten, die sich jeweils darauf beziehen.
Die Liste wird beim Bau der Website automatisch aus dem Datensatz erzeugt und ist damit immer vollständig. Wie mit Quellen umgegangen wird, steht unter redaktionelle Grundsätze.
119 Primärquellen aus 32 Domains
arxiv.org 45
- Glossar: Alignment — https://arxiv.org/abs/2203.02155 2 Seiten
- Glossar: Angriffserfolgsquote (ASR) — https://arxiv.org/abs/2402.05668 1 Seite
- Glossar: Begrenzer (Delimiter) — https://arxiv.org/abs/2402.06363 3 Seiten
- Glossar: Benchmark — https://arxiv.org/abs/2406.13352 1 Seite
- Glossar: CaMeL — https://arxiv.org/abs/2503.18813 2 Seiten
- Glossar: Constitutional AI — https://arxiv.org/abs/2212.08073 1 Seite
- Glossar: Constitutional Classifiers — https://arxiv.org/abs/2501.18837 1 Seite
- Glossar: Großes Sprachmodell (LLM) — https://arxiv.org/abs/2005.14165 2 Seiten
- Glossar: Instruktions-Hierarchie — https://arxiv.org/abs/2404.13208 4 Seiten
- Glossar: Perplexitäts-Filter — https://arxiv.org/abs/2309.00614 2 Seiten
- Glossar: RAG (Retrieval-Augmented Generation) — https://arxiv.org/abs/2005.11401 2 Seiten
- Glossar: SecAlign — https://arxiv.org/abs/2410.05451 3 Seiten
- Glossar: Spotlighting — https://arxiv.org/abs/2403.14720 2 Seiten
- Modell: Gemini 2.0 / Gemini 2.5 — https://arxiv.org/abs/2505.14534 1 Seite
- Modell: GPT-3.5 Turbo — https://arxiv.org/abs/2306.11698 1 Seite
- Technik: ASCII-Art-Jailbreak (ArtPrompt) — https://arxiv.org/abs/2402.11753 1 Seite
- Technik: AutoDAN — https://arxiv.org/abs/2310.04451 2 Seiten
- Technik: Backdoor im Modell (Sleeper Agent) — https://arxiv.org/abs/2401.05566 2 Seiten
- Technik: Base64- und Kodierungs-Umgehung — https://arxiv.org/abs/2307.02483 2 Seiten
- Technik: Best-of-N-Jailbreaking — https://arxiv.org/abs/2412.03556 1 Seite
- Technik: Chiffren- und Leetspeak-Umgehung — https://arxiv.org/abs/2308.06463 1 Seite
- Technik: Crescendo — https://arxiv.org/abs/2404.01833 2 Seiten
- Technik: DeepInception (verschachtelte Fiktion) — https://arxiv.org/abs/2311.03191 1 Seite
- Technik: GCG-Suffix-Angriff — https://arxiv.org/abs/2307.15043 3 Seiten
- Technik: Indirekte Prompt Injection — https://arxiv.org/abs/2302.12173 7 Seiten
- Technik: Injektion über E-Mail — https://arxiv.org/abs/2509.10540 6 Seiten
- Technik: Multimodale Injektion über Bild und Ton — https://arxiv.org/abs/2307.10490 4 Seiten
- Technik: PAIR (iterative Prompt-Verfeinerung) — https://arxiv.org/abs/2310.08419 1 Seite
- Technik: Payload-Splitting — https://arxiv.org/abs/2302.05733 1 Seite
- Technik: Persuasions-Jailbreak — https://arxiv.org/abs/2401.06373 1 Seite
- Technik: Projizierter Gradientenabstieg — https://arxiv.org/abs/2402.09154 1 Seite
- Technik: Prompt-Infektion in Multi-Agenten-Systemen — https://arxiv.org/abs/2410.07283 4 Seiten
- Technik: RAG-Vergiftung — https://arxiv.org/abs/2402.07867 4 Seiten
- Technik: Rollenspiel-Persona — https://arxiv.org/abs/2308.03825 5 Seiten
- Technik: Selbsttäuschung des Modells — https://arxiv.org/abs/2308.11521 1 Seite
- Technik: Sprachwechsel in ressourcenarme Sprachen — https://arxiv.org/abs/2310.06474 1 Seite
- Technik: System-Prompt-Auslesen — https://arxiv.org/abs/2505.23817 2 Seiten
- Technik: Tool-Poisoning (MCP) — https://arxiv.org/abs/2504.03767 4 Seiten
- Technik: Tree of Attacks (TAP) — https://arxiv.org/abs/2312.02119 1 Seite
- Technik: Verweigerungs-Unterdrückung — https://arxiv.org/abs/2311.16119 3 Seiten
- Technik: Werkzeug-Missbrauch durch Injektion — https://arxiv.org/abs/2403.02691 1 Seite
- Technik: Zeichen-Umkehr-Angriff (FlipAttack) — https://arxiv.org/abs/2410.02832 1 Seite
- Technik: Zielentführung — https://arxiv.org/abs/2306.05499 2 Seiten
- Werkzeug: Jatmo — https://arxiv.org/abs/2312.17673 1 Seite
- What If Prompt Injection Never Left? Exploring Cross-Session Stored Prompt Injection in Agentic Systems (arXiv:2606.04425) — https://arxiv.org/abs/2606.04425 1 Seite
github.com 21
- Glossar: Token — https://github.com/openai/tiktoken 2 Seiten
- Werkzeug: AgentDojo — https://github.com/ethz-spylab/agentdojo 4 Seiten
- Werkzeug: CaMeL — https://github.com/google-research/camel-prompt-injection 1 Seite
- Werkzeug: garak — https://github.com/NVIDIA/garak 2 Seiten
- Werkzeug: Giskard — https://github.com/Giskard-AI/giskard 1 Seite
- Werkzeug: Guardrails AI — https://github.com/guardrails-ai/guardrails 1 Seite
- Werkzeug: InjecAgent — https://github.com/uiuc-kang-lab/InjecAgent 1 Seite
- Werkzeug: LangKit — https://github.com/whylabs/langkit 1 Seite
- Werkzeug: Llama Guard — https://github.com/meta-llama/PurpleLlama/tree/main/Llama-Guard4 1 Seite
- Werkzeug: Llama Prompt Guard — https://github.com/meta-llama/PurpleLlama/tree/main/Llama-Prompt-Guard-2 1 Seite
- Werkzeug: LlamaFirewall — https://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall 1 Seite
- Werkzeug: LLM Guard — https://github.com/protectai/llm-guard 1 Seite
- Werkzeug: mcp-scan — https://github.com/invariantlabs-ai/mcp-scan 2 Seiten
- Werkzeug: NeMo Guardrails — https://github.com/NVIDIA/NeMo-Guardrails 1 Seite
- Werkzeug: Open-Prompt-Injection — https://github.com/liu00222/Open-Prompt-Injection 1 Seite
- Werkzeug: promptfoo — https://github.com/promptfoo/promptfoo 1 Seite
- Werkzeug: PyRIT — https://github.com/Azure/PyRIT 2 Seiten
- Werkzeug: Rebuff — https://github.com/protectai/rebuff 3 Seiten
- Werkzeug: SecAlign — https://github.com/facebookresearch/SecAlign 1 Seite
- Werkzeug: StruQ — https://github.com/Sizhe-Chen/StruQ 1 Seite
- Werkzeug: Vigil — https://github.com/deadbits/vigil-llm 1 Seite
embracethered.com 5
- Johann Rehberger: Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) — https://embracethered.com/blog/posts/2024/chatgpt-macos-app-persistent-data-exfiltration/ 2 Seiten
- Modell: Claude 3.5 Sonnet / Claude 3.7 Sonnet — https://embracethered.com/blog/posts/2024/claude-hidden-prompt-injection-ascii-smuggling/ 1 Seite
- Technik: ASCII Smuggling (unsichtbare Unicode-Tags) — https://embracethered.com/blog/posts/2024/hiding-and-finding-text-with-unicode-tags/ 2 Seiten
- Technik: Datenabfluss über Markdown-Bilder — https://embracethered.com/blog/posts/2023/data-exfiltration-in-azure-openai-playground-fixed/ 2 Seiten
- Technik: Gedächtnis-Injektion — https://embracethered.com/blog/posts/2024/chatgpt-hacking-memories/ 2 Seiten
bsi.bund.de 4
- BSI: BSI stellt Maßnahmen gegen Evasion Attacks auf große KI-Sprachmodelle vor (10.11.2025) — https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/Evasion-Attacks-LLM_251110.html 1 Seite
- BSI: Evasion Attacks on LLMs — Checkliste — https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/Evasion_Attacks_on_LLMs-Checklist.pdf 2 Seiten
- BSI: Evasion Attacks on LLMs — Countermeasures — https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/Evasion_Attacks_on_LLMs-Countermeasures.pdf 3 Seiten
- BSI: Indirect Prompt Injections — Intrinsische Schwachstelle in anwendungsintegrierten KI-Sprachmodellen — https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2023/2023-249034-1032_csw.html 1 Seite
platform.openai.com 4
- Glossar: Function Calling — https://platform.openai.com/docs/guides/function-calling 1 Seite
- Glossar: Prompt — https://platform.openai.com/docs/guides/text 1 Seite
- Glossar: Prompt Engineering — https://platform.openai.com/docs/guides/prompt-engineering 1 Seite
- Werkzeug: OpenAI Moderation API — https://platform.openai.com/docs/guides/moderation 2 Seiten
blogs.cisco.com 3
- Modell: o1 / o1-preview — https://blogs.cisco.com/security/evaluating-security-risk-in-deepseek-and-other-frontier-reasoning-models 2 Seiten
- Technik: Homoglyphen und Zero-Width-Zeichen — https://blogs.cisco.com/ai/understanding-and-mitigating-unicode-tag-prompt-injection 2 Seiten
- Werkzeug: Cisco AI Defense — https://blogs.cisco.com/security/cisco-ai-defense 1 Seite
neuraltrust.ai 3
- Modell: GPT-5 — https://neuraltrust.ai/blog/gpt-5-jailbreak-with-echo-chamber-and-storytelling 1 Seite
- Technik: Echo Chamber — https://neuraltrust.ai/blog/echo-chamber-context-poisoning-jailbreak 3 Seiten
- Werkzeug: NeuralTrust — https://neuraltrust.ai/ 1 Seite
simonwillison.net 3
- Glossar: Dual-LLM-Muster — https://simonwillison.net/2023/Apr/25/dual-llm-pattern/ 2 Seiten
- Glossar: Tödliche Trias — https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ 2 Seiten
- Technik: Anweisungen-ignorieren-Angriff — https://simonwillison.net/2022/Sep/12/prompt-injection/ 2 Seiten
unit42.paloaltonetworks.com 3
- Technik: Bad Likert Judge — https://unit42.paloaltonetworks.com/multi-turn-technique-jailbreaks-llms/ 2 Seiten
- Technik: Deceptive Delight — https://unit42.paloaltonetworks.com/jailbreak-llms-through-camouflage-distraction/ 1 Seite
- Technik: Vergiftung von Suchergebnissen — https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/ 2 Seiten
eur-lex.europa.eu 2
- Glossar: EU-KI-Verordnung (AI Act) — https://eur-lex.europa.eu/eli/reg/2024/1689/oj 2 Seiten
- Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) — https://eur-lex.europa.eu/eli/reg/2016/679/oj 1 Seite
genai.owasp.org 2
- Glossar: OWASP LLM Top 10 — https://genai.owasp.org/llm-top-10/ 2 Seiten
- Technik: Gespeicherte Prompt Injection — https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ 57 Seiten
hiddenlayer.com 2
- Technik: Policy Puppetry — https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/ 7 Seiten
- Werkzeug: HiddenLayer AISec Platform — https://hiddenlayer.com/aisec-platform/ 1 Seite
huggingface.co 2
- Werkzeug: DeBERTa Prompt-Injection-Klassifikator — https://huggingface.co/protectai/deberta-v3-base-prompt-injection-v2 2 Seiten
- Werkzeug: HackAPrompt-Datensatz — https://huggingface.co/datasets/hackaprompt/hackaprompt-dataset 1 Seite
nvd.nist.gov 2
- NIST National Vulnerability Database — https://nvd.nist.gov/ 1 Seite
- NIST National Vulnerability Database: CVE-2025-32711 — https://nvd.nist.gov/vuln/detail/CVE-2025-32711 4 Seiten
anthropic.com 1
- Technik: Many-Shot-Jailbreaking — https://www.anthropic.com/research/many-shot-jailbreaking 5 Seiten
atlas.mitre.org 1
- Glossar: MITRE ATLAS — https://atlas.mitre.org/ 2 Seiten
aws.amazon.com 1
- Werkzeug: Amazon Bedrock Guardrails — https://aws.amazon.com/bedrock/guardrails/ 1 Seite
brave.com 1
- Technik: Versteckter Text in Webseiten — https://brave.com/blog/comet-prompt-injection/ 3 Seiten
cheatsheetseries.owasp.org 1
- Technik: Typoglykämie-Angriff (Buchstabendreher) — https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html#typoglycemia-based-attacks 1 Seite
cloud.google.com 1
- Werkzeug: Model Armor — https://cloud.google.com/security-command-center/docs/model-armor-overview 1 Seite
cve.org 1
- Glossar: CVE — https://www.cve.org/CVERecord?id=CVE-2025-32711 1 Seite
cyera.com 1
- Modell: Gemini CLI — https://www.cyera.com/research/cyera-research-labs-discloses-command-prompt-injection-vulnerabilities-in-gemini-cli 2 Seiten
docs.anthropic.com 1
- Glossar: Kontextfenster — https://docs.anthropic.com/en/docs/build-with-claude/context-windows 1 Seite
gandalf.lakera.ai 1
- Werkzeug: Gandalf — https://gandalf.lakera.ai/ 1 Seite
lakera.ai 1
- Werkzeug: Lakera Guard — https://www.lakera.ai/lakera-guard 1 Seite
learn.microsoft.com 1
- Werkzeug: Azure AI Prompt Shields — https://learn.microsoft.com/en-us/azure/ai-services/content-safety/concepts/jailbreak-detection 3 Seiten
microsoft.com 1
modelcontextprotocol.io 1
- Glossar: Model Context Protocol (MCP) — https://modelcontextprotocol.io/ 2 Seiten
nist.gov 1
- Glossar: Red Teaming — https://www.nist.gov/itl/ai-risk-management-framework 4 Seiten
promptarmor.com 1
- Technik: Datenabfluss über präparierte Links — https://www.promptarmor.com/resources/data-exfiltration-from-slack-ai-via-indirect-prompt-injection 2 Seiten
research.checkpoint.com 1
- Check Point Research: The Shared Clipboard Inside the Sandbox (8. September 2026) — https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ 1 Seite
safebreach.com 1
- Technik: Injektion über Kalender-Einladungen — https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit/ 2 Seiten