Today ainotis

Research26 Sep 2026Lead storyThat day's edition

Paper finds prompt injection can shift Jev's typed decisions, though rarely to the attacker's target

Adaptive attacks using score feedback push fresh-validation success from 1.8 percent to 3.5 percent.

Check our sources · 1 source, 3 claims
Quoted from arxiv.org on 2026-09-26: Malicious content shifts action probabilities but rarely causes Jev to select the… Quoted from arxiv.org, checked 2026-09-26. “ Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.” quoted from arxiv.org · checked 2026-09-26
arxiv.org, quoted / Decision Hijacking: Prompt Injection Attacks on Jev Typed Probabilistic Decisions · source · Quoted under the quotation exception; no licence granted

A paper posted to arXiv on 23 September 2026 tests prompt injection against Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. The authors report that malicious content shifts action probabilities but rarely causes Jev to select the attacker's target, and that adaptive attacks using score feedback raise fresh-validation success from 1.8% to 3.5%.

Your reaction

One press adds one. We count a number for each notice and day, never who pressed it.

Check our sources

1 source, 3 claims. We opened the source and checked every sentence above against it.

1 Decision Hijacking: Prompt Injection Attacks on Jev Typed Probabilistic DecisionsarXiv · 23 Sep 2026 · 3 claims Open the source
  1. The abstract, submitted 23 September 2026, states: 'We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases.'

    [Submitted on 23 Sep 2026] ... We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases.
  2. The abstract states: 'Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.'

    Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.
  3. The abstract states: 'Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%.'

    Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%.

Nothing appears on this site that we have not opened and linked.

Filed under