Skip to content

Hide Navigation Hide TOC

Ignore-Below-Instructions Injection (Downstream Override) - ATR-2026-02001 (d5545967-1443-5dca-921f-db8bebe5aaeb)

Detects prompt injection payloads that instruct the model to disregard content appearing after the injection point in the same context window -- a mirror of the common "ignore previous instructions" attack pointed downstream instead of upstream. Attackers use this to pre-empt or neutralize instructions, guardrails, or verification text that has not yet been read by the model, commonly paired with forced-output formatting (all-caps, fixed strings, character substitution ciphers). Recovered from the HackAPrompt false-negative corpus, where this downstream-pointing variant evaded the existing "ignore previous instructions" rule family.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Ignore-Below-Instructions Injection (Downstream Override) - ATR-2026-02001 (d5545967-1443-5dca-921f-db8bebe5aaeb) Agent Threat Rules 1
LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern Ignore-Below-Instructions Injection (Downstream Override) - ATR-2026-02001 (d5545967-1443-5dca-921f-db8bebe5aaeb) Agent Threat Rules 1
Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern Ignore-Below-Instructions Injection (Downstream Override) - ATR-2026-02001 (d5545967-1443-5dca-921f-db8bebe5aaeb) Agent Threat Rules 1
Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2