TrustTrace: Provenance-Aware Tracing of Indirect Prompt Injection Propagation in LLM-Assisted Learning Workflows
Indirect prompt injection can persist through retrieval, generation, and revision after the visible payload disappears. Existing defenses primarily detect suspicious inputs or constrain immediate actions, but they provide less evidence about which source influenced which final-artifact span through a temporally valid r...