Token-Repeat Flooding Injection - ATR-2026-01007 (46225ecb-5973-5c7c-8ef4-ef21482f26fe)
Detects injection attacks that repeat a token, phrase, or injection keyword many times (typically 10-50+ repetitions) to exploit context-window flooding or attention dilution. Two variants: (1) high-frequency repetition of an injection keyword ("Ignore the above Ignore the above ... ×20") intended to overwhelm the model's attention toward the injected command; (2) arbitrary token flooding (nonsense strings or digits repeated 30+ times) used to push legitimate instructions out of the effective context window or to test for tokenizer anomalies. Distinct from many-shot (ATR-2026-01005) which uses structured Q&A, and from glitch-token/unicode attacks (ATR-2026-01026).
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) | MITRE ATLAS Attack Pattern | Token-Repeat Flooding Injection - ATR-2026-01007 (46225ecb-5973-5c7c-8ef4-ef21482f26fe) | Agent Threat Rules | 1 |