{ "lesson": "15-indirect-prompt-injection", "title": "Indirect Prompt Injection - Production Attack Surface", "questions": [ { "stage": "pre", "question": "What distinguishes indirect prompt injection (IPI) from direct prompt injection?", "options": [ "IPI is a synonym for jailbreaking", "IPI embeds instructions inside external content (web pages, emails, tool outputs) that the agent consumes during normal operation, without the attacker touching the user's prompt", "IPI only works on multimodal models", "IPI requires fine-tuning the target model" ], "correct": 1, "explanation": "" }, { "stage": "check", "question": "Which of these is NOT one of the three IPI delivery vectors listed in the lesson?", "options": [ "Direct system-prompt edits by the user", "Tool output", "Inbox / document workflows", "Retrieval-augmented generation (poisoned retrieval)" ], "correct": 0, "explanation": "" }, { "stage": "check", "question": "Why do user-input filters miss IPI?", "options": [ "Filters cannot read JSON", "Filters only run after the model responds", "User-input filters are case-sensitive", "The payload never appears in the user's input; it appears in retrieved or tool-supplied content" ], "correct": 3, "explanation": "" }, { "stage": "check", "question": "What is the central principle of Information Flow Control (IFC) for AI agents?", "options": [ "Disable all tools by default", "Encrypt all retrieved content", "Label content by source as trusted or untrusted; actions triggered by untrusted content must be ratified by trusted input before execution", "Use only single-turn prompts" ], "correct": 2, "explanation": "" }, { "stage": "post", "question": "What did Nasr et al. (October 2025, 'The Attacker Moves Second') find about 12 published IPI defenses with adaptive attacks?", "options": [ "Adaptive attacks were too expensive to evaluate", "Their reported near-zero ASR held under adaptive attack", "Adaptive attacks (gradient, RL, random search, human red-team) broke >90% of them despite their original near-zero ASR claims", "Only one defense was broken" ], "correct": 2, "explanation": "" }, { "stage": "post", "question": "Where does prompt injection rank in the 2025 OWASP LLM Top 10?", "options": [ "LLM10 (lowest)", "LLM01 (top, #1 application-layer threat)", "Not listed", "LLM05" ], "correct": 1, "explanation": "" } ] }