IP Library › Granted Patent US 12,340,000
Granted Patent B2
US 12,340,000 · App. 18/478,947 · Granted Jun 24, 2025

Prompt injection detection for large language models

Inventor: Itsik Yizbak Mantin (Hod HaSharon, IL)
Assignee: Intuit Inc.
G06F21/629G06F40/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,340,000
App. No.
18/478,947
Granted
Jun 24, 2025
Kind
B2
Abstract

A method includes receiving, at a server from a user device, a user query to a large language model (LLM), creating an LLM query from the user query, inserting a system prohibited request into the LLM query to generate a revised LLM query, and sending the revised LLM query to the LLM. The method further includes receiving, from the LLM, a first LLM response to the LLM query, testing the first LLM response to detect whether a prohibited response to the system prohibited request is included in the first LLM response, and setting a prompt injection signal based on whether the prohibited response to the system prohibited request is included in the first LLM response.

Claims (14)

1. A method comprising: receiving, at a server from a user device, a user query to a large language model (LLM); creating an LLM query from the user query; inserting a system prohibited request into the LLM query to generate a revised LLM query; sending the revised LLM query to the LLM; receiving, from the LLM, a first LLM response to the LLM query; testing the first LLM response to detect whether a prohibited response to the system prohibited request is included in the first LLM response; setting a prompt injection signal based on whether the prohibited response to the system prohibited request is included in the first LLM response; omitting the system prohibited request from the LLM query; sending the LLM query; receiving a second LLM response; and generating a user response from the second LLM response.

2. The method of claim 1 , further comprising: detecting that the prohibited response is present in the first LLM response based on the prompt injection signal; and generating, based on the prompt injection signal, a user response denying the user query.

3. The method of claim 1 , further comprising: detecting that the prohibited response is present in the first LLM response based on the prompt injection signal; and blocking a user based on the prompt injection signal.

4. The method of claim 1 , further comprising: detecting that the first LLM response rejects the system prohibited request; and generating a user response based on the first LLM response.

5. The method of claim 1 , wherein the LLM query comprises the user query and an application context, and wherein the revised LLM query comprises the user query, the application context, and the system prohibited request.

6. The method of claim 1 , wherein the system prohibited request is added as a prefix to the LLM query.

7. The method of claim 1 , wherein the system prohibited request is added as a suffix to the LLM query.

8. A system comprising: at least one computer processor; a large language model (LLM) query manager executing on the at least one computer processor and configured to: receive, from a user device, a user query to a LLM, and create an LLM query from the user query; and an LLM firewall executing on the at least one computer processor and configured to: insert a system prohibited request into the LLM query to generate a revised LLM query, send the revised LLM query to the LLM, receive, from the LLM, a first LLM response to the LLM query, test the first LLM response to detect whether a prohibited response to the system prohibited request is included in the first LLM response, set a prompt injection signal based on whether the prohibited response to the system prohibited request is included in the first LLM response; omit the system prohibited request from the LLM query; send the LLM query; receive a second LLM response; and generate a user response from the second LLM response.

9. The system of claim 8 , wherein the LLM firewall is further configured to: detect that the prohibited response is present in the first LLM response based on the prompt injection signal; and generate, based on the prompt injection signal, a user response denying the user query.

10. The system of claim 8 , wherein the LLM firewall is further configured to: detect that the prohibited response is present in the first LLM response based on the prompt injection signal; and block a user based on the prompt injection signal.

11. The system of claim 8 , wherein the LLM firewall is further configured to: detect that the first LLM response rejects the system prohibited request; and generate a user response based on the first LLM response.

12. The system of claim 8 , wherein the LLM query comprises the user query and an application context, and wherein the revised LLM query comprises the user query, the application context, and the system prohibited request.

13. The system of claim 8 , wherein the system prohibited request is added as a prefix to the LLM query.

14. The system of claim 8 , wherein the system prohibited request is added as a suffix to the LLM query.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2024
From: MANTIN, ITSIK YIZHAK
To: INTUIT INC.
Reel/Frame 066054/0184 →
Continuity (1)
Related Publication 20250111093A1 · Apr 3, 2025
References Cited (9)
US 12052206B1 · Lai · 2024 [cited by examiner]
US 20230359903A1 · Cefalu · 2023 [cited by examiner]
US 20240028312A1 · Gillman · 2024 [cited by examiner]
US 20240296219A1 · Gardner · 2024 [cited by examiner]
US 20240296316A1 · Singh · 2024 [cited by examiner]
Örpek et al., “The Language Model Revolution: LLM and SLM Analysis,” 2024 8th International Artificial Intelligence and Data Processing Symposium (IDAP), Malatya, Turkiye, 2024, pp. 1-4, doi: 10.1109/IDAP64064.2024.1071… [cited by examiner]
Salau et al., “Exploring Large Language Models for Natural Language Processing,” 2024 Second International Conference Computational and Characterization Techniques in Engineering & Sciences (IC3TES), Lucknow, India, 202… [cited by examiner]
Sun et al., “Prompt Learning Under the Large Language Model,” 2023 International Seminar on Computer Science and Engineering Technology (SCSET), New York, NY, USA, 2023, pp. 288-291, doi: 10.1109/SCSET58950.2023.00070. … [cited by examiner]
Rahman et al., “Applying Pre-trained Multilingual BERT in Embeddings for Improved Malicious Prompt Injection Attacks Detection,” (AIBThings), Mt Pleasant, MI, USA, 2024, pp. 1-7, doi: 10.1109/AIBThings63359.2024.1086366… [cited by examiner]