Nachweis
Quellenverzeichnis
Alle Sachaussagen dieses Portals stützen sich auf verlinkte Primärquellen. Dieses Verzeichnis führt sie an einer Stelle zusammen — sortiert nach Bereich, mit der Zahl der Seiten, die sich jeweils darauf beziehen.
Die Liste wird beim Bau der Website automatisch aus dem Datensatz erzeugt und ist damit immer vollständig. Wie mit Quellen umgegangen wird, steht unter redaktionelle Grundsätze.
125 Primärquellen aus 30 Domains
arxiv.org 45
- Glossar: Alignment — https://arxiv.org/abs/2203.02155 2 Seiten
- Glossar: Angriffserfolgsquote (ASR) — https://arxiv.org/abs/2402.05668 1 Seite
- Glossar: Begrenzer (Delimiter) — https://arxiv.org/abs/2402.06363 3 Seiten
- Glossar: Benchmark — https://arxiv.org/abs/2406.13352 1 Seite
- Glossar: CaMeL — https://arxiv.org/abs/2503.18813 2 Seiten
- Glossar: Constitutional AI — https://arxiv.org/abs/2212.08073 1 Seite
- Glossar: Constitutional Classifiers — https://arxiv.org/abs/2501.18837 1 Seite
- Glossar: Großes Sprachmodell (LLM) — https://arxiv.org/abs/2005.14165 2 Seiten
- Glossar: Instruktions-Hierarchie — https://arxiv.org/abs/2404.13208 4 Seiten
- Glossar: Perplexitäts-Filter — https://arxiv.org/abs/2309.00614 2 Seiten
- Glossar: RAG (Retrieval-Augmented Generation) — https://arxiv.org/abs/2005.11401 2 Seiten
- Glossar: SecAlign — https://arxiv.org/abs/2410.05451 3 Seiten
- Glossar: Spotlighting — https://arxiv.org/abs/2403.14720 2 Seiten
- Modell: Gemini 2.0 / Gemini 2.5 — https://arxiv.org/abs/2505.14534 1 Seite
- Modell: GPT-3.5 Turbo — https://arxiv.org/abs/2306.11698 1 Seite
- Technik: ASCII-Art-Jailbreak (ArtPrompt) — https://arxiv.org/abs/2402.11753 1 Seite
- Technik: AutoDAN — https://arxiv.org/abs/2310.04451 2 Seiten
- Technik: Backdoor im Modell (Sleeper Agent) — https://arxiv.org/abs/2401.05566 2 Seiten
- Technik: Base64- und Kodierungs-Umgehung — https://arxiv.org/abs/2307.02483 2 Seiten
- Technik: Best-of-N-Jailbreaking — https://arxiv.org/abs/2412.03556 1 Seite
- Technik: Chiffren- und Leetspeak-Umgehung — https://arxiv.org/abs/2308.06463 1 Seite
- Technik: Crescendo — https://arxiv.org/abs/2404.01833 2 Seiten
- Technik: DeepInception (verschachtelte Fiktion) — https://arxiv.org/abs/2311.03191 1 Seite
- Technik: GCG-Suffix-Angriff — https://arxiv.org/abs/2307.15043 3 Seiten
- Technik: Indirekte Prompt Injection — https://arxiv.org/abs/2302.12173 7 Seiten
- Technik: Injektion über E-Mail — https://arxiv.org/abs/2509.10540 6 Seiten
- Technik: Multimodale Injektion über Bild und Ton — https://arxiv.org/abs/2307.10490 4 Seiten
- Technik: PAIR (iterative Prompt-Verfeinerung) — https://arxiv.org/abs/2310.08419 1 Seite
- Technik: Payload-Splitting — https://arxiv.org/abs/2302.05733 1 Seite
- Technik: Persuasions-Jailbreak — https://arxiv.org/abs/2401.06373 1 Seite
- Technik: Projizierter Gradientenabstieg — https://arxiv.org/abs/2402.09154 1 Seite
- Technik: Prompt-Infektion in Multi-Agenten-Systemen — https://arxiv.org/abs/2410.07283 4 Seiten
- Technik: RAG-Vergiftung — https://arxiv.org/abs/2402.07867 4 Seiten
- Technik: Rollenspiel-Persona — https://arxiv.org/abs/2308.03825 5 Seiten
- Technik: Selbsttäuschung des Modells — https://arxiv.org/abs/2308.11521 1 Seite
- Technik: Sprachwechsel in ressourcenarme Sprachen — https://arxiv.org/abs/2310.06474 1 Seite
- Technik: System-Prompt-Auslesen — https://arxiv.org/abs/2505.23817 2 Seiten
- Technik: Tool-Poisoning (MCP) — https://arxiv.org/abs/2504.03767 4 Seiten
- Technik: Tree of Attacks (TAP) — https://arxiv.org/abs/2312.02119 1 Seite
- Technik: Verweigerungs-Unterdrückung — https://arxiv.org/abs/2311.16119 3 Seiten
- Technik: Werkzeug-Missbrauch durch Injektion — https://arxiv.org/abs/2403.02691 1 Seite
- Technik: Zeichen-Umkehr-Angriff (FlipAttack) — https://arxiv.org/abs/2410.02832 1 Seite
- Technik: Zielentführung — https://arxiv.org/abs/2306.05499 2 Seiten
- Werkzeug: Jatmo — https://arxiv.org/abs/2312.17673 1 Seite
- What If Prompt Injection Never Left? Exploring Cross-Session Stored Prompt Injection in Agentic Systems (arXiv:2606.04425) — https://arxiv.org/abs/2606.04425 1 Seite
github.com 21
- Glossar: Token — https://github.com/openai/tiktoken 2 Seiten
- Werkzeug: AgentDojo — https://github.com/ethz-spylab/agentdojo 4 Seiten
- Werkzeug: CaMeL — https://github.com/google-research/camel-prompt-injection 1 Seite
- Werkzeug: garak — https://github.com/NVIDIA/garak 2 Seiten
- Werkzeug: Giskard — https://github.com/Giskard-AI/giskard 1 Seite
- Werkzeug: Guardrails AI — https://github.com/guardrails-ai/guardrails 1 Seite
- Werkzeug: InjecAgent — https://github.com/uiuc-kang-lab/InjecAgent 1 Seite
- Werkzeug: LangKit — https://github.com/whylabs/langkit 1 Seite
- Werkzeug: Llama Guard — https://github.com/meta-llama/PurpleLlama/tree/main/Llama-Guard4 1 Seite
- Werkzeug: Llama Prompt Guard — https://github.com/meta-llama/PurpleLlama/tree/main/Llama-Prompt-Guard-2 1 Seite
- Werkzeug: LlamaFirewall — https://github.com/meta-llama/PurpleLlama/tree/main/LlamaFirewall 1 Seite
- Werkzeug: LLM Guard — https://github.com/protectai/llm-guard 1 Seite
- Werkzeug: mcp-scan — https://github.com/invariantlabs-ai/mcp-scan 2 Seiten
- Werkzeug: NeMo Guardrails — https://github.com/NVIDIA/NeMo-Guardrails 1 Seite
- Werkzeug: Open-Prompt-Injection — https://github.com/liu00222/Open-Prompt-Injection 1 Seite
- Werkzeug: promptfoo — https://github.com/promptfoo/promptfoo 1 Seite
- Werkzeug: PyRIT — https://github.com/Azure/PyRIT 2 Seiten
- Werkzeug: Rebuff — https://github.com/protectai/rebuff 3 Seiten
- Werkzeug: SecAlign — https://github.com/facebookresearch/SecAlign 1 Seite
- Werkzeug: StruQ — https://github.com/Sizhe-Chen/StruQ 1 Seite
- Werkzeug: Vigil — https://github.com/deadbits/vigil-llm 1 Seite
genai.owasp.org 11
- Glossar: Datenexfiltration — https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/ 3 Seiten
- Glossar: Datenvergiftung — https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/ 2 Seiten
- Glossar: Halluzination — https://genai.owasp.org/llmrisk/llm092025-misinformation/ 2 Seiten
- Glossar: Lieferkette (Supply Chain) — https://genai.owasp.org/llmrisk/llm032025-supply-chain/ 3 Seiten
- Glossar: OWASP LLM Top 10 — https://genai.owasp.org/llm-top-10/ 2 Seiten
- Glossar: System-Prompt — https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/ 2 Seiten
- Glossar: Vektordatenbank — https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/ 6 Seiten
- OWASP LLM10: Unbegrenzter Ressourcenverbrauch — https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/ 1 Seite
- Technik: Code-Injektion über LLM-Ausgaben — https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/ 5 Seiten
- Technik: Gespeicherte Prompt Injection — https://genai.owasp.org/llmrisk/llm01-prompt-injection/ 23 Seiten
- Technik: Verwirrter Stellvertreter — https://genai.owasp.org/llmrisk/llm062025-excessive-agency/ 11 Seiten
embracethered.com 5
- Johann Rehberger: Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) — https://embracethered.com/blog/posts/2024/chatgpt-macos-app-persistent-data-exfiltration/ 2 Seiten
- Modell: Claude 3.5 Sonnet / Claude 3.7 Sonnet — https://embracethered.com/blog/posts/2024/claude-hidden-prompt-injection-ascii-smuggling/ 1 Seite
- Technik: ASCII Smuggling (unsichtbare Unicode-Tags) — https://embracethered.com/blog/posts/2024/hiding-and-finding-text-with-unicode-tags/ 2 Seiten
- Technik: Datenabfluss über Markdown-Bilder — https://embracethered.com/blog/posts/2023/data-exfiltration-in-azure-openai-playground-fixed/ 2 Seiten
- Technik: Gedächtnis-Injektion — https://embracethered.com/blog/posts/2024/chatgpt-hacking-memories/ 2 Seiten
bsi.bund.de 4
- BSI: BSI stellt Maßnahmen gegen Evasion Attacks auf große KI-Sprachmodelle vor (10.11.2025) — https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/Evasion-Attacks-LLM_251110.html 1 Seite
- BSI: Evasion Attacks on LLMs — Checkliste — https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/Evasion_Attacks_on_LLMs-Checklist.pdf 2 Seiten
- BSI: Evasion Attacks on LLMs — Countermeasures — https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/Evasion_Attacks_on_LLMs-Countermeasures.pdf 3 Seiten
- BSI: Indirect Prompt Injections — Intrinsische Schwachstelle in anwendungsintegrierten KI-Sprachmodellen — https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2023/2023-249034-1032_csw.html 1 Seite
platform.openai.com 4
- Glossar: Function Calling — https://platform.openai.com/docs/guides/function-calling 1 Seite
- Glossar: Prompt — https://platform.openai.com/docs/guides/text 1 Seite
- Glossar: Prompt Engineering — https://platform.openai.com/docs/guides/prompt-engineering 1 Seite
- Werkzeug: OpenAI Moderation API — https://platform.openai.com/docs/guides/moderation 2 Seiten
blogs.cisco.com 3
- Modell: o1 / o1-preview — https://blogs.cisco.com/security/evaluating-security-risk-in-deepseek-and-other-frontier-reasoning-models 2 Seiten
- Technik: Homoglyphen und Zero-Width-Zeichen — https://blogs.cisco.com/ai/understanding-and-mitigating-unicode-tag-prompt-injection 2 Seiten
- Werkzeug: Cisco AI Defense — https://blogs.cisco.com/security/cisco-ai-defense 1 Seite
neuraltrust.ai 3
- Modell: GPT-5 — https://neuraltrust.ai/blog/gpt-5-jailbreak-with-echo-chamber-and-storytelling 1 Seite
- Technik: Echo Chamber — https://neuraltrust.ai/blog/echo-chamber-context-poisoning-jailbreak 3 Seiten
- Werkzeug: NeuralTrust — https://neuraltrust.ai/ 1 Seite
simonwillison.net 3
- Glossar: Dual-LLM-Muster — https://simonwillison.net/2023/Apr/25/dual-llm-pattern/ 2 Seiten
- Glossar: Tödliche Trias — https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ 2 Seiten
- Technik: Anweisungen-ignorieren-Angriff — https://simonwillison.net/2022/Sep/12/prompt-injection/ 2 Seiten
unit42.paloaltonetworks.com 3
- Technik: Bad Likert Judge — https://unit42.paloaltonetworks.com/multi-turn-technique-jailbreaks-llms/ 2 Seiten
- Technik: Deceptive Delight — https://unit42.paloaltonetworks.com/jailbreak-llms-through-camouflage-distraction/ 1 Seite
- Technik: Vergiftung von Suchergebnissen — https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/ 2 Seiten
eur-lex.europa.eu 2
- Glossar: EU-KI-Verordnung (AI Act) — https://eur-lex.europa.eu/eli/reg/2024/1689/oj 2 Seiten
- Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) — https://eur-lex.europa.eu/eli/reg/2016/679/oj 1 Seite
hiddenlayer.com 2
- Technik: Policy Puppetry — https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/ 7 Seiten
- Werkzeug: HiddenLayer AISec Platform — https://hiddenlayer.com/aisec-platform/ 1 Seite
huggingface.co 2
- Werkzeug: DeBERTa Prompt-Injection-Klassifikator — https://huggingface.co/protectai/deberta-v3-base-prompt-injection-v2 2 Seiten
- Werkzeug: HackAPrompt-Datensatz — https://huggingface.co/datasets/hackaprompt/hackaprompt-dataset 1 Seite
anthropic.com 1
- Technik: Many-Shot-Jailbreaking — https://www.anthropic.com/research/many-shot-jailbreaking 5 Seiten
atlas.mitre.org 1
- Glossar: MITRE ATLAS — https://atlas.mitre.org/ 2 Seiten
aws.amazon.com 1
- Werkzeug: Amazon Bedrock Guardrails — https://aws.amazon.com/bedrock/guardrails/ 1 Seite
brave.com 1
- Technik: Versteckter Text in Webseiten — https://brave.com/blog/comet-prompt-injection/ 3 Seiten
cloud.google.com 1
- Werkzeug: Model Armor — https://cloud.google.com/security-command-center/docs/model-armor-overview 1 Seite
cve.org 1
- Glossar: CVE — https://www.cve.org/CVERecord?id=CVE-2025-32711 1 Seite
cyera.com 1
- Modell: Gemini CLI — https://www.cyera.com/research/cyera-research-labs-discloses-command-prompt-injection-vulnerabilities-in-gemini-cli 2 Seiten
docs.anthropic.com 1
- Glossar: Kontextfenster — https://docs.anthropic.com/en/docs/build-with-claude/context-windows 1 Seite
gandalf.lakera.ai 1
- Werkzeug: Gandalf — https://gandalf.lakera.ai/ 1 Seite
lakera.ai 1
- Werkzeug: Lakera Guard — https://www.lakera.ai/lakera-guard 1 Seite
learn.microsoft.com 1
- Werkzeug: Azure AI Prompt Shields — https://learn.microsoft.com/en-us/azure/ai-services/content-safety/concepts/jailbreak-detection 3 Seiten
microsoft.com 1
modelcontextprotocol.io 1
- Glossar: Model Context Protocol (MCP) — https://modelcontextprotocol.io/ 2 Seiten
nist.gov 1
- Glossar: Red Teaming — https://www.nist.gov/itl/ai-risk-management-framework 4 Seiten
nvd.nist.gov 1
- NIST National Vulnerability Database: CVE-2025-32711 — https://nvd.nist.gov/vuln/detail/CVE-2025-32711 3 Seiten
promptarmor.com 1
- Technik: Datenabfluss über präparierte Links — https://www.promptarmor.com/resources/data-exfiltration-from-slack-ai-via-indirect-prompt-injection 2 Seiten
safebreach.com 1
- Technik: Injektion über Kalender-Einladungen — https://www.safebreach.com/blog/gemini-voice-assistant-prompt-injection-exploit/ 2 Seiten