@inproceedings{adenuga-2026-linguistic,
title = "A Linguistic Analysis of Prompt Injection in Large Language Models",
author = "Adenuga, Priscilla",
editor = "Mitkov, Ruslan and
Mu{\~n}oz, Rafael and
Lloret, Elena and
Ranasinghe, Tharindu and
Estevanell-Valladares, Ernesto L. and
Lamsiyah, Salima and
Montoyo, Andr{\'e}s and
Ezzini, Saad",
booktitle = "Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security",
month = jun,
year = "2026",
address = "Alicante, Spain",
publisher = "Department of Languages and Information Systems, University of Alicante",
url = "https://aclanthology.org/2026.nlpaics-1.17/",
pages = "163--170",
abstract = "Large Language Models (LLMs) are increasingly deployed across a wide range of applications, from conversational assistants to decision support systems. However, these systems remain vulnerable to prompt injection attacks, in which carefully crafted inputs manipulate model behavior and circumvent intended safeguards. While existing research has largely approached prompt injection as a technical or security problem, the linguistic mechanisms through which such attacks operate remain insufficiently understood. In this paper, we argue that prompt injection attacks are fundamentally linguistic in nature, exploiting discourse structure, pragmatic framing, and instruction hierarchies encoded in natural language prompts. Drawing on concepts from speech act theory, discourse analysis, and pragmatics, we propose a typology of four linguistic strategies used to manipulate Large Language Models: instruction override, role framing, hypothetical framing, and procedural prompting. Through detailed linguistic analysis of representative examples, we demonstrate how each strategy exploits identifiable properties of natural language interaction to reshape model interpretation and influence output generation. For each strategy, we also discuss implications for detection and mitigation, arguing that effective safeguards must attend to discourse-level patterns in prompts rather than relying solely on surface-level keyword filtering. Our findings contribute to emerging research at the intersection of computational linguistics and AI security and highlight the importance of integrating linguistic expertise into the design of more robust and reliable language-based AI systems."
}<?xml version="1.0" encoding="UTF-8"?>
<modsCollection xmlns="http://www.loc.gov/mods/v3">
<mods ID="adenuga-2026-linguistic">
<titleInfo>
<title>A Linguistic Analysis of Prompt Injection in Large Language Models</title>
</titleInfo>
<name type="personal">
<namePart type="given">Priscilla</namePart>
<namePart type="family">Adenuga</namePart>
<role>
<roleTerm authority="marcrelator" type="text">author</roleTerm>
</role>
</name>
<originInfo>
<dateIssued>2026-06</dateIssued>
</originInfo>
<typeOfResource>text</typeOfResource>
<relatedItem type="host">
<titleInfo>
<title>Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security</title>
</titleInfo>
<name type="personal">
<namePart type="given">Ruslan</namePart>
<namePart type="family">Mitkov</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Rafael</namePart>
<namePart type="family">Muñoz</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Elena</namePart>
<namePart type="family">Lloret</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Tharindu</namePart>
<namePart type="family">Ranasinghe</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Ernesto</namePart>
<namePart type="given">L</namePart>
<namePart type="family">Estevanell-Valladares</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Salima</namePart>
<namePart type="family">Lamsiyah</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Andrés</namePart>
<namePart type="family">Montoyo</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<name type="personal">
<namePart type="given">Saad</namePart>
<namePart type="family">Ezzini</namePart>
<role>
<roleTerm authority="marcrelator" type="text">editor</roleTerm>
</role>
</name>
<originInfo>
<publisher>Department of Languages and Information Systems, University of Alicante</publisher>
<place>
<placeTerm type="text">Alicante, Spain</placeTerm>
</place>
</originInfo>
<genre authority="marcgt">conference publication</genre>
</relatedItem>
<abstract>Large Language Models (LLMs) are increasingly deployed across a wide range of applications, from conversational assistants to decision support systems. However, these systems remain vulnerable to prompt injection attacks, in which carefully crafted inputs manipulate model behavior and circumvent intended safeguards. While existing research has largely approached prompt injection as a technical or security problem, the linguistic mechanisms through which such attacks operate remain insufficiently understood. In this paper, we argue that prompt injection attacks are fundamentally linguistic in nature, exploiting discourse structure, pragmatic framing, and instruction hierarchies encoded in natural language prompts. Drawing on concepts from speech act theory, discourse analysis, and pragmatics, we propose a typology of four linguistic strategies used to manipulate Large Language Models: instruction override, role framing, hypothetical framing, and procedural prompting. Through detailed linguistic analysis of representative examples, we demonstrate how each strategy exploits identifiable properties of natural language interaction to reshape model interpretation and influence output generation. For each strategy, we also discuss implications for detection and mitigation, arguing that effective safeguards must attend to discourse-level patterns in prompts rather than relying solely on surface-level keyword filtering. Our findings contribute to emerging research at the intersection of computational linguistics and AI security and highlight the importance of integrating linguistic expertise into the design of more robust and reliable language-based AI systems.</abstract>
<identifier type="citekey">adenuga-2026-linguistic</identifier>
<location>
<url>https://aclanthology.org/2026.nlpaics-1.17/</url>
</location>
<part>
<date>2026-06</date>
<extent unit="page">
<start>163</start>
<end>170</end>
</extent>
</part>
</mods>
</modsCollection>
%0 Conference Proceedings
%T A Linguistic Analysis of Prompt Injection in Large Language Models
%A Adenuga, Priscilla
%Y Mitkov, Ruslan
%Y Muñoz, Rafael
%Y Lloret, Elena
%Y Ranasinghe, Tharindu
%Y Estevanell-Valladares, Ernesto L.
%Y Lamsiyah, Salima
%Y Montoyo, Andrés
%Y Ezzini, Saad
%S Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security
%D 2026
%8 June
%I Department of Languages and Information Systems, University of Alicante
%C Alicante, Spain
%F adenuga-2026-linguistic
%X Large Language Models (LLMs) are increasingly deployed across a wide range of applications, from conversational assistants to decision support systems. However, these systems remain vulnerable to prompt injection attacks, in which carefully crafted inputs manipulate model behavior and circumvent intended safeguards. While existing research has largely approached prompt injection as a technical or security problem, the linguistic mechanisms through which such attacks operate remain insufficiently understood. In this paper, we argue that prompt injection attacks are fundamentally linguistic in nature, exploiting discourse structure, pragmatic framing, and instruction hierarchies encoded in natural language prompts. Drawing on concepts from speech act theory, discourse analysis, and pragmatics, we propose a typology of four linguistic strategies used to manipulate Large Language Models: instruction override, role framing, hypothetical framing, and procedural prompting. Through detailed linguistic analysis of representative examples, we demonstrate how each strategy exploits identifiable properties of natural language interaction to reshape model interpretation and influence output generation. For each strategy, we also discuss implications for detection and mitigation, arguing that effective safeguards must attend to discourse-level patterns in prompts rather than relying solely on surface-level keyword filtering. Our findings contribute to emerging research at the intersection of computational linguistics and AI security and highlight the importance of integrating linguistic expertise into the design of more robust and reliable language-based AI systems.
%U https://aclanthology.org/2026.nlpaics-1.17/
%P 163-170
Markdown (Informal)
[A Linguistic Analysis of Prompt Injection in Large Language Models](https://aclanthology.org/2026.nlpaics-1.17/) (Adenuga, NLPAICS 2026)
ACL
- Priscilla Adenuga. 2026. A Linguistic Analysis of Prompt Injection in Large Language Models. In Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security, pages 163–170, Alicante, Spain. Department of Languages and Information Systems, University of Alicante.