ALGORITHM FOR FILTERING "HINT INJECTIONS" WHEN USING SPATIAL INFORMATION

Abstract

The integration of large language models (LLM) into geographic information systems (GIS) opens up new opportunities for spatial analysis, but it is accompanied by specific vulnerabilities such as "hint injection" (prompt injection). Such attacks allow attackers to bypass LLM security mechanisms, manipulate issuance, gain access to confidential information, and violate data integrity. Using space allows you to access an object not directly, but through its spatial relationships with other objects. Existing keyword or template filtering methods do not provide reliable protection due to the constant emergence of new attack scenarios. This determines the relevance of developing adaptive, self-learning algorithms for filtering queries for industrial injections to large language models. The aim of the study is to develop an algorithm for filtering prompt injections for LLM, based on the Case-Based Reasoning (CBR) method. The paper proposes an algorithm for comparing LLM queries with a database of previously known promt injections. The experiment showed that as the database of use cases accumulates, the accuracy of detecting prompt injections increases from 42% to 83%. At the same time, the processing time for a single request increases slightly (from 0.18 to 0.19 seconds with a 23% increase in the database). Approaches to generalizing the precedent base and introspection of the precedent base were also proposed. The proposed algorithm makes it possible to increase the security of LLM-interface systems against prompt injections due to adaptivity and self-learning. The practical significance lies in the possibility of implementing the developed filter into information systems to prevent leaks and manipulation of spatial data. Further research is related to the development of methods for automatic generalization of use cases and the integration of additional contextual analyzers.

##article.references##

1. Şekeroğlu A., Çelik K.T. Integration of AI, Spatial Data, and GIS in Planning: Spatial Application Based on Machine Learning and Deep Learning, ICONARP International Journal of Architecture and Planning, 2025, Vol. 13, No. 2, pp. 592-624. DOI: 10.15320/ICONARP.2025.337.

2. Pierdicca R., Muralikrishna N., Tonetto F., Ghianda A. On the Use of LLMs for GIS-Based Spatial Analysis, ISPRS International Journal of Geo-Information, 2025, Vol. 14, No. 10, Art. 401. DOI: 10.3390/ijgi14100401.

3. Li Y., Liu Y., Wang J., Zhang H. A Question-Answering Framework for Geospatial Data Retrieval En-hanced by a Knowledge Graph and Large Language Models, International Journal of Digital Earth, 2024, Vol. 18 (1). DOI: 10.3390/ijgi14100401.

4. Khandelwal U., Levy O., Jurafsky D., Zettlemoyer L., Lewis M. Generalization through Memorization: Nearest Neighbor Language Models, arXiv.org, 2019. Available at: https://arxiv.org/abs/1911.00172.

5. Gurnee W., Tegmark M. Language Models Represent Space and Time, arXiv.org, 2023. Available at: https://doi.org/10.48550/arXiv.2310.02207.

6. Chang Z., Li M., Wang J., Qing Y., Yang J. Play Guessing Game with LLM: Indirect Jailbreak Attack with Implicit Clues, arXiv.org, 2024. Available at: https://doi.org/10.48550/arXiv.2402.09091.

7. Zyryanova I.N., Chernavskiy A.S., Trubachev S.O. Prompt injection - problema lingvisticheskikh uyazvimostey bol'shikh yazykovykh modeley na sovremennom etape [Prompt injection - problema lingvisticheskikh uyazvimostey bol'shikh yazykovykh modeley na sovremennom etape], Nauchnyy rezu-l'tat. Voprosy teoreticheskoy i prikladnoy lingvistiki [Scientific Result. Issues of Theoretical and Applied Linguistics], 2024, Vol. 10, No. 4, pp. 40-52. DOI: 10.18413/2313-8912-2024-10-4-0-3.

8. Konev A.A., Payusova T.I. Podkhod k otsenke kachestva generatsii stsenariev pentesta pri pomoshchi bol'shikh yazykovykh modeley [An approach to assessing the quality of pentest scenario generation using large language models], Voprosy kiberbezopasnosti [Cybersecurity Issues], 2025, No. 6 (70),

pp. 147-157. DOI: 10.21681/2311-3456-2025-6-147-157.

9. Ggaliwango M., Nakayiza H.R., Daudi J., Nakatumba-Nabende J. Prompt engineering in large language models // Proceedings of the International conference on data intelligence and cognitive informatics, Data Intelligence and Cognitive Informatics: ICDICI 2023. Algorithms for Intelligent Systems. Singapore: Springer, 2024, pp. 387-401. DOI: 10.1007/978-981-99-7962-2 30.

10. Mudarova R.M, Namiot D.E. Protivodeystvie atakam tipa in"ektsiya podskazok na bol'shie yazykovye modeli [Countering hint injection attacks on large language models], International Journal of Open Infor-mation Technologies, 2024, Vol. 12, No. 5, pp. 39-48.

11. Bethany M., et al. Large Language Model Lateral Spear Phishing: A Comparative Study in Large-Scale Organizational Settings, arXiv.org, 2024. Available at: https://doi.org/10.48550/arXiv.2311.11538.

12. Namiot D.E., Il'yushin E.A. O kiberriskakh generativnogo iskusstvennogo intellekta [On the cyber risks of generative artificial intelligence], International Journal of Open Information Technologies, 2024, Vol. 12, No. 10, pp. 109-119.

13. Yu J., Wu S., Dong J., Yang S., Xing X. Assessing Prompt Injection Risks in 200+ Custom GPTs, arXiv.org, 2023. Available at: https://doi.org/10.48550/arXiv.2311.11538.

14. Kotenko I.V., Abramenko G.T. Ispol'zovanie bol'shikh yazykovykh modeley dlya poiska ugroz kiber-bezopasnosti na osnove metodov glubokogo obucheniya: analiz sovremennykh issledovaniy [Using large language models to detect cybersecurity threats based on deep learning methods: an analysis of current re-search], Pravovaya informatika [Legal Informatics], 2024, No. 1, pp. 63-72.

15. Chernyy yashchik raskryt: kak in"ektsiya promta zastavlyaet II govorit' vse i vytyagivaet sistemnyy zapros [Black Box Uncovered: How Prompt Injection Makes AI Say Everything and Extracts System Requests]. Available at: https://habr.com/ru/companies/bothub/articles/904950 (accessed 20 April 2026).

16. Yan J., Yadav V., Li S., et al. Backdooring instruction-tuned large language models with virtual prompt injection, Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Vol. 1, pp. 6065-6086. DOI: 10.18653/v1/2024.naacl-long.337.

17. Evglevskaya N.V., Kazantsev A.A. Metodika povysheniya zashchishchennosti LLM-servisov s prime-neniem LLM Security Proxy [Methodology for increasing the security of LLM services using LLM Secu-rity Proxy], Ekonomika i kachestvo sistem svyazi [Economics and quality of communication systems], 2026, No. 1, pp. 185-193.

18. Shulha O., Yanenkova I., Kuzub M., Muda I., Nazarenko V. Banking information resource cybersecurity system modeling, Journal of Open Innovation: Technology, Market, and Complexity, 2022, Vol. 8 (2), pp. 80.

19. Chastikova V.A., Bakhtin A.S., Merkulov P.A. Razrabotka metodiki integratsii bol'shikh yazykovykh mod-eley v protsessy tsentra monitoringa informatsionnoy bezopasnosti [Development of a methodology for integrating large language models into the processes of an information security monitoring center], Izvesti-ya YuFU. Tekhnicheskie nauki [Izvestiya SFedU. Engineering Sciences], 2025, No. 4 (246), pp. 57-69.

20. Martino A., Iannelli M., Truong C. Knowledge injection to counter large language model (LLM) halluci-nation, European Semantic Web Conference. Cham: Springer Nature Switzerland, 2023, pp. 182-185.

21. Ye H. et al. Ontology-enhanced Prompt-tuning for Few-shot Learning, Proceedings of the ACM Web Con-ference 2022, 2022, pp. 778-787.

22. Goyal S., Doddapaneni S., Khapra M.M., Ravindran B. A Survey of Adversarial Defences and Robust-ness in NLP, arXiv.org, 2023, 43 p. Available at: https://doi.org/10.48550/arXiv.2203.06414.

23. Sharma R.K., Gupta V., Grossman D. SPML: A DSL for Defending Language Models Against Prompt Attacks School of Computer Science & Engineering, arXiv.org, 2024. Available at: https://doi.org/10.48550/arXiv.2402.11755.

24. Yu Z., Liu X., Liang S., Cameron Z., Xiao C., Zhang N. Don't listen to me: understanding and exploring jailbreak prompts of large language models, arXiv.org, 2024. Available at: https://doi.org/ 10.48550/arXiv.2403.17336.

25. OpenAI Guardrails: zashchita II-prilozheniy ot atak [OpenAI Guardrails: Protecting AI Applications from Attacks]. Available at: https://habr.com/ru/articles/968516/ (accessed 20 April 2026).

26. Li Z., Ning H. Autonomous GIS: The next-generation AI-powered GIS, International Journal of Digital Earth, 2023, Vol. 16, No. 2, pp. 4668-4686. DOI: 10.1080/17538947.2023.2278895.

27. Hahsler M., Piekenbrock M., Doran D. dbscan: Fast Density-Based Clustering with R, Journal of Statis-tical Software, 2019, Vol. 91, No. 1. DOI: 10.18637/jss.v091.i01.

Скачивания

##article.published##:

2026-07-07

##article.issue##:

##article.section##:

SECTION II. PROTECTION METHODS AND SECURITY TECHNOLOGIES

DOI:

Keywords:

Prompt injection, LLM, Large language models, attacks on models, GIS modeling, CBR

##submission.сitation##:

Belyakov S.L. , Izrailev L.А. , Pokusaev О.N. ALGORITHM FOR FILTERING "HINT INJECTIONS" WHEN USING SPATIAL INFORMATION. IZVESTIYA SFedU. ENGINEERING SCIENCES. – 2026. - № 3. – ##article.page##. 32-45.