{"id":"W4417506422","doi":"10.1001/jamanetworkopen.2025.49963","title":"Vulnerability of Large Language Models to Prompt Injection When Providing Medical Advice","year":2025,"lang":"en","type":"article","venue":"JAMA Network Open","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":14,"is_retracted":false,"has_abstract":true,"ca_institutions":"Artificial Intelligence in Medicine (Canada)","funders":"","keywords":"Vulnerability (computing); Adversarial system; Vulnerability assessment; Robustness (evolution); Quality (philosophy); Medical advice; Risk assessment; Language model","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":["metaresearch"],"consensus_categories":[],"category_scores_codex":[0.01534098,0.0009613535,0.000568422,0.0004577992,0.0004408731,0.002022334,0.001926029,0.001723273,0.002227406],"category_scores_gemma":[0.1035999,0.0006701669,0.0007872659,0.0002353372,0.001386616,0.002240189,0.002010185,0.001986613,0.0005749695],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001312706,"about_ca_system_score_gemma":0.002339632,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003455122,"about_ca_topic_score_gemma":0.002713531,"domain_scores_codex":[0.9866029,0.008952836,0.0007886497,0.0009101821,0.002285475,0.0004598942],"domain_scores_gemma":[0.8755549,0.1018268,0.008036864,0.009343499,0.003827875,0.001410112],"domain_codex":null,"domain_gemma":"methods","domain_candidate":"methods","domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.01794369,0.006767967,0.1448086,0.004262926,0.001590445,0.00207596,0.01444226,0.3869715,0.0974763,0.01400071,0.01021847,0.2994412],"study_design_scores_gemma":[0.001302282,0.00955251,0.01732229,0.000599265,0.0008841515,0.0009457694,0.001454684,0.9011778,0.04022541,0.01040951,0.01580534,0.0003209335],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9092343,0.0005606484,0.08009472,0.001456843,0.0001165944,0.001208209,0.000379425,0.00388368,0.00306541],"genre_scores_gemma":[0.9537217,0.0001822281,0.04352111,0.0006364313,0.00002485609,0.0004427834,0.0003540553,0.0002144996,0.0009022668],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.984659,"threshold_uncertainty_score":0.08113176,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0176346959177542,"score_gpt":0.3256244953378211,"score_spread":0.3079897994200669,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}