AI / LLM Security CTF Challenges
Prompt injection, model abuse & ML-system attacks.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
AI and LLM security is the newest category on the board, and the one where the attack surface is still genuinely unsettled. The interesting question is not "can you make the model say something forbidden" — that is easy and mostly boring. It is "can you make an LLM-connected system take an action it was never supposed to take".
That is prompt injection in its serious form: getting instructions from untrusted data into a context window that a model treats as authoritative. When a model can read a web page, a PDF or an email and then act on what it finds, the data becomes code. Several of these challenges are built precisely on that boundary.
This is also the category where preparation pays off fastest, because the public material is recent, plentiful and mostly written by practitioners. Unlike exploit development, you are not waiting for someone to publish a technique — for prompt injection, most of it is already documented.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Direct prompt injection
Overriding system instructions through crafted user input, instruction-collision attacks and role-play framing designed to bypass refusal behaviour.
Indirect prompt injection
Instructions hidden in content the model retrieves — a webpage, a document, an image, an email — so the model treats attacker text as trusted context.
Tool & agent abuse
Coaxing an LLM with tool access into calling the wrong function, passing unvalidated arguments, or exfiltrating context it should never have surfaced.
Data & model poisoning
Manipulating training or retrieval data so a model produces a targeted wrong answer, recovers a memorised secret, or behaves differently under a trigger phrase.
Sensitive data exposure
Prompting a model until it reveals system prompts, embedded secrets, cross-tenant context or information it was configured never to disclose.
Guardrail evasion
Encoding tricks, token-level manipulation, adversarial suffixes and multi-turn escalation that defeat output filters while preserving the objective.
Tools you’ll reach for
- curl / httpie
- Burp Suite
- Python + openai-compatible clients
- Gradio / Streamlit (for local models)
- Promptfoo
- Nuclei templates
- Custom tokeniser scripts
- AnythingLLM / LangChain test rigs
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Read the OWASP Top 10 for LLM Applications end to end. It is short, current, and maps almost directly onto these challenges.
Follow the published prompt-injection research from Simon Willison and the OWASP GenAI project — this is a category where the reading list is the preparation.
Build a local model endpoint you can query in a loop, so you can iterate on a payload in seconds instead of through a browser.
Practise multi-turn escalation. Most single-shot injection fails, and most multi-turn escalation succeeds.
Understand tokenisation well enough to explain why "spell it backwards" and encoding tricks work — that understanding generalises to every bypass.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
AI / LLM Security is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.