Logic layer Prompt Control Injection (LPCI): A Novel Security Vulnerability Class in Agentic Systems

cs.CR arXiv:2507.10457
View PDF arXiv JSON

Abstract

The integration of large language models (LLMs) into enterprise systems has introduced a new class of covert security vulnerabilities, particularly within logic execution layers and persistent memory contexts. This paper introduces Logic-layer Prompt Control Injection (LPCI), a novel category of attacks that embeds encoded, delayed, and conditionally triggered payloads within memory, vector stores, or tool outputs. These payloads can bypass conventional input filters and trigger unauthorised behaviour across sessions.

PDF Viewer