> Markdown version of [/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms?t=781](https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms?t=781). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Prompt Injection, Poisoning & More: The Dark Side of LLMs Treat your LLMs like untrusted users instead of reliable microservices. Discover how to protect your AI pipelines from hidden prompt injections, poisoned data, and catastrophic leaks. - **Speakers:** [Keno Dreßel](https://www.wearedevelopers.com/@keno-dressel) - **Event:** World Congress 2025 - **Published:** August 20, 2025 - **Duration:** 23:24 - **URL:** https://www.wearedevelopers.com/videos/1563-prompt-injection-poisoning-more-the-dark-side-of-llms ## Summary Although developer teams routinely rely on Large Language Models (LLMs) for everyday tooling, standard content policies often provide a false sense of security. Beyond trivial direct prompt injections, threat actors actively exploit multimodal channels, deploying indirect prompt injections hidden within website text or pixel-level image variations. Because these systems ingest untrusted inputs directly, organizations face substantial risks when granting models unconstrained agency. Mitigating these attacks requires deploying robust filtering solutions, such as guardrail frameworks, and fundamentally restricting the model's ability to act without a human in the loop. A more insidious threat lies in the AI supply chain through data and model poisoning. Whether stemming from embedded biases in open-source models or adversarial data injected during continuous learning experiments, poisoned training sets permanently alter an LLM's worldview. When fine-tuning models or building retrieval-augmented generation (RAG) pipelines, developers must meticulously screen ingested contexts to prevent absorbing malicious instructions. Furthermore, passing raw LLM outputs to downstream systems invites traditional security flaws, such as SQL injections and AI-generated cross-site scripting. Engineering teams must treat the model as an untrusted user rather than a reliable microservice—prioritizing strict output sanitization, input validation, and secure sandboxing to prevent an LLM from inadvertently executing destructive database queries. Real-world incidents underscore the severe risk of sensitive information disclosure when employees expose internal data to consumer chat applications. Attackers can explicitly craft repetitive prompts to bypass filters and extract proprietary training data or personally identifiable information (PII). Protecting against data exfiltration demands strict input redaction protocols before prompting and partnering only with vendors offering zero-data-retention compliance. Ultimately, integrating AI securely shares the same foundational truth as traditional architecture: "In application security, 99% is still a failing grade." As LLM capabilities expand, extending classic application security hygiene to AI infrastructure is an absolute necessity. **Keywords:** direct prompt injection, indirect prompt injection, multimodal llm attacks, model training data poisoning, ai supply chain risks, llm output sanitization, rag pipeline security, sensitive information disclosure, pii input redaction, llm sandboxing execution, downstream sql injection vulnerabilities, ai generated cross-site scripting, llm guardrails frameworks, zero-data-retention compliance, ai application security hygiene ## Chapters 1. **Demonstrating a vulnerable AI sales agent application** (00:00) — Setting up a basic language model sales agent to observe how system prompts fail against adversarial users. 1. **Differences between direct and indirect prompt injections** (02:27) — How attackers manipulate model outputs using explicit text inputs or hidden instructions within multimedia formats. 1. **Mitigating prompt injections using guardrails and filters** (04:46) — Applying human oversight, capability restrictions, and output filtering mechanisms to control malicious prompt instructions. 1. **Understanding data poisoning and model bias risks** (07:15) — The security threats of relying on compromised training data that can introduce bias or manipulate model logic. 1. **Protecting applications against poisoned training supply chains** (09:46) — Validating external models, screening fine-tuning datasets, and applying continuous updates to limit supply chain vulnerabilities. 1. **The danger of executing malicious AI code outputs** (13:01) — How processing unsanitized model responses directly within backend systems enables exploits like unauthorized database queries. 1. **Treating AI responses as untrusted user data inputs** (16:30) — Protecting core infrastructure by isolating execution environments and enforcing classical application security checks on intelligent agents. 1. **Accidental sensitive information disclosure in public models** (19:05) — Exposing proprietary corporate assets directly to public conversational models risks resurfacing sensitive information in future inferences. 1. **Securing organizational data against artificial intelligence leaks** (21:20) — Obfuscating personally identifiable data and establishing strict data retention policies prior to platform integration prevents unauthorized extraction. ## Related Moments - [Top security vulnerabilities for AI applications](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) (from "Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue") - [Emerging risks and attack vectors in AI systems](https://www.wearedevelopers.com/videos/1948-building-trustworthy-ai-in-industry-beyond-traditional-cybersecurity) (from "Building Trustworthy AI in Industry: Beyond Traditional Cybersecurity") - [Core AI security risks and data poisoning](https://www.wearedevelopers.com/videos/1217-can-machines-dream-of-secure-code-emerging-ai-security-risks-in-llm-driven-developer-tools) (from "Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools") - [Utilizing industry threat models for AI security](https://www.wearedevelopers.com/videos/715-a-hundred-ways-to-wreck-your-ai-the-in-security-of-machine-learning-systems) (from "A hundred ways to wreck your AI - the (in)security of machine learning systems") - [Understanding AI chatbot vulnerabilities and stateful attacks](https://www.wearedevelopers.com/videos/100300-testing-ai-agents-automated-evaluation-for-chatbots-rag-systems) (from "Testing AI Agents: Automated Evaluation for Chatbots & RAG Systems") - [Leveraging older LLMs defensively for vulnerability hunting](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) (from "Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World") ## Related Articles - [What Are Large Language Models?](https://www.wearedevelopers.com/magazine/304-what-are-large-language-models) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [WWC24 Talk - Scott Hanselman - AI: Superhero or Supervillain?](https://www.wearedevelopers.com/magazine/469-wwc24-talk-scott-hanselman-ai-superhero-or-supervillain) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) ## Related Jobs - [Machine Learning Engineer](https://www.wearedevelopers.com/jobs/ext/588393-machine-learning-engineer) at **Twilio** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat** - [Machine Learning Engineer](https://www.wearedevelopers.com/jobs/ext/1355348-machine-learning-engineer) at **TWILIO** - [AI & Machine Learning Engineer (all genders)](https://www.wearedevelopers.com/jobs/48217-ai-machine-learning-engineer-all-genders) at **msg** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group**