AI · Public research briefing
Architecture-Level Attack Vectors Against LLM Systems
RAG, vector embeddings, agent tools, and dependency risks
A technical threat-model briefing on indirect prompt injection, embedding exposure, excessive agent permissions, and supply-chain risks in modern LLM systems.
The question
“Recent successful and emerging attack vectors targeting Large Language Models focus heavily on architecture-level flaws rather than traditional code execution: * **Indirect Prompt Injection via RAG & External Content:** Attackers embed malicious instructions within unstructured text (such as shared documents, support tickets, or web pages) processed by Retrieval-Augmented Generation pipelines. Because LLMs conflate data and control instructions, the model executes the injected directives to leak context data or hijack user sessions. * **Vector Embedding Inversion Attacks:** Rather than attacking the model directly, adversaries target underlying vector databases. Using semantic embedding inversion techniques, attackers reconstruct near-exact raw text documents, proprietary code, or credentials from stored mathematical vector representations alone. * **Agentic Tool Abuse & Excessive Agency:** Autonomous AI agents equipped with broader API tools and low-constraint permissions are increasingly vulnerable to multi-step chain exploits, where an injected prompt tricks the agent into misusing internal developer tools or performing unintended lateral actions across connected environments. * **Supply Chain and Dependency Poisoning:** Threat actors compromise upstream components like public model repositories, model configuration files, custom PyPI packages, or MCP (Model Context Protocol) servers to silently introduce backdoors or exfiltrate session secrets during routine execution. Advanced and technical”
Explore the complete package
Ask your own question
Turn a complex question into a source-backed briefing, editable document, podcast, slides, and training video.
Start research