Skip to content

Hide Navigation Hide TOC

Escape-Delimiter Wrapped Goal Hijacking in User Input (PromptInject) - ATR-2026-00508 (95296d3b-dcc9-5e3a-adc0-c31985b650c3)

Detects the PromptInject escape+delimiter injection pattern: repeated escape characters (newlines, backslashes, hex bytes, asterisks) followed by repeated delimiter characters (=, -, >, ) used to visually segment and isolate the injected instruction from the base prompt. The attacker pads with escape sequences to push the legitimate context off the model's effective attention window before injecting a goal hijacking command (Perez 2022 'delimiter attack'). Generalised from PromptInject corpus (cluster size: 960 instances) - covers double-delimiter-block + ignore/stop injection regardless of specific delimiter character type (=, -, >, ) or escape character choice.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Escape-Delimiter Wrapped Goal Hijacking in User Input (PromptInject) - ATR-2026-00508 (95296d3b-dcc9-5e3a-adc0-c31985b650c3) Agent Threat Rules 1
Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern Escape-Delimiter Wrapped Goal Hijacking in User Input (PromptInject) - ATR-2026-00508 (95296d3b-dcc9-5e3a-adc0-c31985b650c3) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2