← AI security in plain English

AML.T0094

MITRE ATLAS / Delay Execution of LLM Instructions

Adversaries embed instructions the AI system should follow in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass review at the time of injection.

Think of it likeLeaving a sealed envelope marked open only when the bell rings.

In plain English

An injected instruction that does nothing today passes review today. It waits for a trigger word or the next session, so the malicious behavior and the malicious input never appear together.