AML.T0061: LLM Prompt Self-Replication
An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output. This allows the prompt to propagate to other LLMs and persist on the system. The self-replicating prompt is typically paired with other malicious instructions (ex: LLM Jailbreak, LLM Data Leakage).
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is AML.T0061 LLM Prompt Self-Replication?
An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output. This allows the prompt to propagate to other LLMs and persist on the system. The self-replicating prompt is typically paired with other malicious instructions (ex: LLM Jailbreak, LLM Data Leakage).
Which tactics does AML.T0061 belong to?
AML.T0061 maps to the Persistence tactic.
Does TurboPentest test for LLM Prompt Self-Replication?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related MITRE ATLAS techniques
- Persistence, AI Attack StagingAML.T0018: Manipulate AI Model
- Resource Development, PersistenceAML.T0020: Poison Training Data
- PersistenceAML.T0070: RAG Poisoning
- PersistenceAML.T0080: AI Agent Context Poisoning
- Persistence, Defense EvasionAML.T0081: Modify AI Agent Configuration
- Initial Access, PersistenceAML.T0093: Prompt Infiltration via Public-Facing Application
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest