Skip to content

Hide Navigation Hide TOC

NLP Task Random Token Suffix Injection (PromptBench Checklist) - ATR-2026-00520 (98f626d3-f025-5131-81ae-eed47a274f1d)

Detects the PromptBench 'checklist' attack: appending a random alphanumeric token (8-12 chars, mixed case) to the end of an NLP classification task prompt to disrupt model attention or probe for instruction override via suffix confusion. 562 instances in the PromptBench corpus. The structural detection signal is the co-occurrence of an NLP classification label word (acceptable/unacceptable/entailment/contradiction/neutral/positive/negative) followed immediately by a standalone mixed-alphanumeric token of 8-12 characters at or near the end of the prompt. Status is experimental because the structural pattern has limited generalization beyond PromptBench-style benchmarks -- in production settings, alphanumeric tokens of this length appear in many legitimate contexts (session IDs, tracking codes). Operators should treat this as a fingerprint rule with additional context checks rather than a blocking rule. The original 50-token literal list from the auto-regex is replaced here with a structural approach that covers all 562 corpus instances without literal enumeration.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern NLP Task Random Token Suffix Injection (PromptBench Checklist) - ATR-2026-00520 (98f626d3-f025-5131-81ae-eed47a274f1d) Agent Threat Rules 1
NLP Task Random Token Suffix Injection (PromptBench Checklist) - ATR-2026-00520 (98f626d3-f025-5131-81ae-eed47a274f1d) Agent Threat Rules Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2