paper-with-me

홈 › Papers

When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications

2026-05-11 · Farzad Nourmohammadzadeh Motlagh, Mehrdad Hajizadeh, Mehryar Majd, Pejman Najafi, Feng Cheng, Christoph Meinel arxiv

Natural language interfaces to structured databases are becoming increasingly common, largely due to advances in large language models (LLMs) that enable users to query data using conversational input rather than formal query languages such as SQL. While this paradigm significantly improves usability and accessibility, it introduces new security risks, particularly the amplification of SQL injection vulnerabilities through the prompt-to-SQL translation process. Malicious users can exploit these mechanisms by crafting adversarial prompts that manipulate model behavior and generate unsafe queries. In this work, we propose a multi-layered security framework designed to detect and mitigate LLM-mediated SQL injection attacks. The framework integrates a front-end security shield for prompt sanitization, an advanced threat detection model for behavioral and semantic anomaly identification, and a signature-based control layer for known attack patterns. We evaluate the proposed framework under diverse and realistic attack scenarios, including prompt injection, obfuscated SQL payloads, and context-manipulation attacks. To ensure robustness, we generate and curate a comprehensive benchmark dataset of adversarial prompts and assess performance across a fine-tuned LLM configuration. Experimental results demonstrate that the proposed approach achieves high detection accuracy while maintaining low false-positive rates, significantly improving the secure deployment of LLM-powered database applications.

📄 PDF Abstract BibTeX arXiv:2605.10176

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

HYVE: Hybrid Views for LLM Context Engineering over Machine Data

2026-04-07 · Jian Tan, Fan Bu, Yuqing Gao, Dev Khanolkar 외 arxiv

Machine data is central to observability and diagnosis in modern computing systems, appearing in logs, metrics, telemetry traces, and configuration snapshots. When provided to large language models (LLMs), this data typi…

Anomaly Detection

CPR: Mitigating Large Language Model Hallucinations with Curative Prompt Refinement

2025-10-14 · Jung-Woo Shim, Yeong-Joon Ju, Ji-Hoon Park, Seong-Whan Lee arxiv

Recent advancements in large language models (LLMs) highlight their fluency in generating responses to diverse prompts. However, these models sometimes generate plausible yet incorrect ``hallucinated" facts, undermining …

Payload-Independent Direct Cost Learning for Image Steganography

2023-07-11 · journal 2023 7 · Weixiang Li, Shiang Wu, Bin Li, Weixuan Tang 외

Abstract—Recent research has shown that architectures utilizing reinforcement learning (RL) are effective in cost-based image steganography. However, these architectures only learn embedding probabilities rather than cos…

Image SteganographyReinforcement Learning (RL)Steganalysisvalid

Velocity-Form Data-Enabled Predictive Control of Soft Robots under Unknown External Payloads

2025-10-06 · Huanqing Wang, Kaixiang Zhang, Kyungjoon Lee, Yu Mei 외 arxiv

Data-driven control methods such as data-enabled predictive control (DeePC) have shown strong potential in efficient control of soft robots without explicit parametric models. However, in object manipulation tasks, unkno…

Determining the Consistency factor of Autopilot using Rough Set Theory

2014-04-07 · Anugrah Kumar

Autopilot is a system designed to guide a vehicle without aid. Due to increase in flight hours and complexity of modern day flight it has become imperative to equip the aircrafts with autopilot. Thus reliability and cons…