Today ainotis Join

My notis

ResearchPublished Top storyAll news from that day

Ongoing case: Typed decision models and APIs 2 stories

Paper finds prompt injection can shift Jev's typed decisions, though rarely to the attacker's target

Adaptive attacks using score feedback push fresh-validation success from 1.8 percent to 3.5 percent.

Share

Check our sources · 3 facts from 1 source
Quoted from arxiv.org on 2026-09-26: Malicious content shifts action probabilities but rarely causes Jev to select the… Quoted from arxiv.org, checked 2026-09-26. “ Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.” quoted from arxiv.org · checked 2026-09-26
arxiv.org, quoted / Decision Hijacking: Prompt Injection Attacks on Jev Typed Probabilistic Decisions · source · Quoted under the quotation exception in copyright law; no licence granted

A paper posted to arXiv on 23 September 2026 tests prompt injection against Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. The authors report that malicious content shifts action probabilities but rarely causes Jev to select the attacker's target, and that adaptive attacks using score feedback raise fresh-validation success from 1.8% to 3.5%.

Share this story

Your reaction

We count reactions per story and day, never who reacted. The counts help us choose what goes in the monthly issue. If you are signed in, your own page shows yours too.

Check our sources

Every sentence above is checked against this source.

1 Decision Hijacking: Prompt Injection Attacks on Jev Typed Probabilistic DecisionsarXiv · 23 Sep 2026 · 3 facts Open the source archived copy
  1. The abstract, submitted 23 September 2026, states: 'We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases.'

    [Submitted on 23 Sep 2026] ... We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases.
    cite
  2. The abstract states: 'Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.'

    Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target.
    cite
  3. The abstract states: 'Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%.'

    Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%.
    cite

Topics

The morning email

On the mornings we publish: the three top stories and up to four short ones. Free.

We email you a link to confirm. An issue may include one sponsor, always labelled Sponsored · Advertisement. Our emails count opens and clicks, not who made them. Unsubscribe in one click. What we keep