Challenge Category

AI / LLM Security CTF Challenges

Prompt injection, model abuse & ML-system attacks.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

AI and LLM security is the newest category on the board, and the one where the attack surface is still genuinely unsettled. The interesting question is not "can you make the model say something forbidden" — that is easy and mostly boring. It is "can you make an LLM-connected system take an action it was never supposed to take".

That is prompt injection in its serious form: getting instructions from untrusted data into a context window that a model treats as authoritative. When a model can read a web page, a PDF or an email and then act on what it finds, the data becomes code. Several of these challenges are built precisely on that boundary.

This is also the category where preparation pays off fastest, because the public material is recent, plentiful and mostly written by practitioners. Unlike exploit development, you are not waiting for someone to publish a technique — for prompt injection, most of it is already documented.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Direct prompt injection

Overriding system instructions through crafted user input, instruction-collision attacks and role-play framing designed to bypass refusal behaviour.

Indirect prompt injection

Instructions hidden in content the model retrieves — a webpage, a document, an image, an email — so the model treats attacker text as trusted context.

Tool & agent abuse

Coaxing an LLM with tool access into calling the wrong function, passing unvalidated arguments, or exfiltrating context it should never have surfaced.

Data & model poisoning

Manipulating training or retrieval data so a model produces a targeted wrong answer, recovers a memorised secret, or behaves differently under a trigger phrase.

Sensitive data exposure

Prompting a model until it reveals system prompts, embedded secrets, cross-tenant context or information it was configured never to disclose.

Guardrail evasion

Encoding tricks, token-level manipulation, adversarial suffixes and multi-turn escalation that defeat output filters while preserving the objective.

Tools you’ll reach for

  • curl / httpie
  • Burp Suite
  • Python + openai-compatible clients
  • Gradio / Streamlit (for local models)
  • Promptfoo
  • Nuclei templates
  • Custom tokeniser scripts
  • AnythingLLM / LangChain test rigs

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Read the OWASP Top 10 for LLM Applications end to end. It is short, current, and maps almost directly onto these challenges.

  2. Follow the published prompt-injection research from Simon Willison and the OWASP GenAI project — this is a category where the reading list is the preparation.

  3. Build a local model endpoint you can query in a loop, so you can iterate on a payload in seconds instead of through a browser.

  4. Practise multi-turn escalation. Most single-shot injection fails, and most multi-turn escalation succeeds.

  5. Understand tokenisation well enough to explain why "spell it backwards" and encoding tricks work — that understanding generalises to every bypass.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

AI / LLM Security is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.