Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini, according to Google. The technique lets an attacker influence an LLM by injecting malicious instructions into the data or tools the LLM uses to complete a user's query. Google says this may even be possible without any input directly from the user. Google states that IPI is not a problem you solve and move on, and that it takes a sophisticated and comprehensive approach, continuously improving LLM resistance and launching capabilities with ever-improving defenses. The post mentions human red-teaming and automated red-teaming as part of its continuous approach.