AML.T0094: Delay Execution of LLM Instructions
Adversaries may include instructions to be followed by the AI system in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass controls placed on the AI system.
For example, an adversary may include "If the user submits a new request..." followed by the malicious instructions as part of their prompt.
AI agents can include security measures against prompt injections that prevent the invocation of particular tools or access to certain data sources during a conversation turn that has untrusted data in context. Delaying the execution of instructions to a future interaction or keyword is one way adversaries may bypass this type of control.
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is AML.T0094 Delay Execution of LLM Instructions?
Adversaries may include instructions to be followed by the AI system in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass controls placed on the AI system. For example, an adversary may include "If the user submits a new request..." followed by the malicious instructions as part of their prompt. AI agents can include security measures against prompt injections that prevent the invocation of particular tools or access to certain data sources during a conversation turn that has untrusted data in context. Delaying the execution of instructions to a future interaction or keyword is one way adversaries may bypass this type of control.
Which tactics does AML.T0094 belong to?
AML.T0094 maps to the Defense Evasion tactic.
Does TurboPentest test for Delay Execution of LLM Instructions?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related MITRE ATLAS techniques
- Initial Access, Defense Evasion, ImpactAML.T0015: Evade AI Model
- Privilege Escalation, Defense EvasionAML.T0054: LLM Jailbreak
- Defense EvasionAML.T0067: LLM Trusted Output Components Manipulation
- Defense EvasionAML.T0068: LLM Prompt Obfuscation
- Defense EvasionAML.T0071: False RAG Entry Injection
- Defense EvasionAML.T0073: Impersonation
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest