cs.CRSep 23, 2026

Decision Hijacking: Prompt Injection Attacks on Jev's Typed Probabilistic Decisions

Authors: Tiantong Wu, Wei Yang Bryan Lim

Organizations: Nanyang Technological University Singapore

Abstract

Most studies of prompt injection focus on generative agents, leaving their effects on models with schema-defined outputs unclear. We examine these effects in Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. Malicious content shifts action probabilities but rarely causes Jev to select the attacker's target. Override markers reduce this influence, while claims of contextual relatedness have small effects. Adaptive attacks using score feedback double the mean highest attacker-target probability found during optimization, while success on fresh validation calls rises from 1.8% to 3.5%. Exploratory analysis links these successes to small initial decision margins or greater attacker control over the observation. Together, these findings show that schema-defined outputs change but do not eliminate prompt-injection risk, highlighting the need to evaluate how untrusted content influences choices within the allowed action set.

Figures & tables

Appendix figures & tables11 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems

    Jul 16, 2026Soham Gadgil, David Alexander, Sai Sunku +1Indirect Prompt InjectionAgentic Memory

  2. Readable Before Actionable: Causal Tracing of Indirect Prompt Injection

    Oct 4, 2026Zhe Yu, Wenpeng Xing, Xingxing Yang +1Indirect Prompt Injection

  3. Prompt Injection as Role Confusion

    Feb 22, 2026Charles Ye, Jasmine Cui, Dylan Hadfield-MenellAttacker Large Language ModelPrompt Engineering