LearnThatStack Ace your next interview
AI Security & Guardrails · question
Question 2 of 55

Explain the difference between direct and indirect prompt injection, with an example of each.

beginner
← All AI Security & Guardrails questions
Re-explain

Direct prompt injection is when the attacker is the user: they type adversarial input straight into the application.

Indirect prompt injection is when malicious instructions arrive through content the model processes on behalf of a legitimate user. A web page it is asked to summarize, an email in an inbox assistant, or a PDF attachment. Other carriers include a calendar invite and a document retrieved by a RAG pipeline.

The victim never typed anything malicious; the payload rode in on data.

Indirect injection is generally considered the more dangerous class. This is because the injected content can target other people, arrives through channels developers often treat as trusted data, and scales. One poisoned document can attack every user whose assistant reads it.

Direct injection is partly a user-abuse problem handled with moderation and rate limits. At the same time, indirect injection demands treating all retrieved or fetched content as untrusted, restricting agent privileges, and gating consequential actions on human review.

Rewriting in plainer words…

This answer doesn't lend itself to a diagram - it reads best . No credits were charged.

Why there's no diagram: “”

The interactive diagram is below the answer - jump to diagram ↓ · Below it, the related concept . Jump to it ↓

The diagram below the answer is the concept . Jump to it ↓

Tailored explanation · switch back to · ·
What should the new diagram focus on?
How well did you know this?
AI:

Saved in this browser - sign in to keep your review list.

How should your speech become text?

Listening… your words appear above as you speak - tap Stop when you're done.

Recording · cr - tap Stop & transcribe when you're done.

Transcribing with AI…

Voice:

Keep going - a few more words and AI can grade it.

Interview lens

Likely follow-ups, what you can say, and the weak answers to avoid.

Sign in free to open it Free account - the lens opens as soon as you're back.

Want a quick review of the fundamentals? See the AI Security & Guardrails cheatsheet.

← Back to all AI Security & Guardrails questions
Pro · $10/mo

48 of 55 AI Security & Guardrails answers are in Pro.

Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.

  • Full answers + code
  • AI explanations, simpler or deeper
  • 1,000 AI credits / month
  • Cancel anytime