Shekar Rao Lakavath · Journal of Computer Science and Information Technology 2026 · 2026
DOI: 10.61424/jcsit.v3i2.1077
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Large language models (LLMs) hosted on Microsoft Azure, primarily through Azure OpenAI Service, are increasingly embedded in enterprise applications that combine user input, retrieved documents, web content, and tool-calling agents within a single prompt context. This architectural pattern, while powerful, collapses the traditional separation between instructions and data and creates a distinct and growing attack surface known as prompt injection. This paper reviews the technical literature on prompt injection and adjacent LLM security threats and maps these threats onto the specific components of an Azure-based generative AI deployment, including Azure OpenAI Service, Azure AI Search, Azure AI Content Safety, and plugin or function-calling integrations built with Logic Apps. We develop a taxonomy of six prompt injection attack categories—direct injection, indirect injection, prompt leaking, jailbreaking, optimisation-based injection, and tool-mediated injection—drawn from the adversarial machine learning and LLM security literature, and we examine six corresponding defense mechanisms available within or alongside the Azure platform. The analysis shows that no single Azure-native control is sufficient on its own: content filtering, programmable guardrails, instruction–data separation, least-privilege tool permissions, content provenance checks, and systematic red-teaming each address a different point in the attack surface and must be layered together. We conclude that securing Azure-hosted LLM applications against prompt injection requires continuous, defense-in-depth engineering rather than a single configuration decision, and we identify open research questions around architectural, rather than purely filter-based, solutions to the instruction–data separation problem.
No comments yet — start the discussion below.