LLM Prompt Injection Awareness & Mitigation Practices Survey
Measures developer awareness of prompt injection threats, captures current security mitigation practices, and identifies gaps in LLM application defense. Designed for engineering teams building or evaluating LLM-integrated features.
設問の例
テンプレートの内容をプレビューできます。すべての設問は公開前に自由に編集できます。
Which area best describes your primary role?
- Back-end engineering
- Front-end engineering
- Full-stack engineering
- Machine learning / data science
- DevOps / SRE
- Security engineering
- QA / Test automation
- Other (please specify)
How confident are you in your personal understanding of prompt injection risks and mitigations?
Which of the following threat vectors do you consider when designing or reviewing LLM features? Select all that apply.
- Prompt injection (malicious instructions in user input)
- Indirect prompt injection via external content sources
- Jailbreaks / model override of system policies
- Data exfiltration or leakage via prompts or responses
- Tool misuse or over-permissioned agent actions
- Training data poisoning
- Prompt leakage or system prompt version exposure
- None of these
Which of the following prompt injection mitigations has your team adopted? Select all that apply.
- Input validation and sanitization of user prompts
- System prompt hardening (e.g., instruction hierarchy, delimiters)
- Output filtering or content safety checks
- Role-based access controls for LLM tool/action permissions
- Monitoring and logging of LLM interactions
- Canary tokens or honeypots in system prompts
- Sandboxing or isolation of LLM execution environments
- None of these
- Not sure
In the last 6 months, have you encountered suspected prompt injection or jailbreak activity in your systems?
- Yes — confirmed incident
- Possibly — suspicious behavior, not confirmed
- No
Rank the following metrics by how much you prioritize them when evaluating prompt injection mitigations (top = highest priority).
- False positive rate (legitimate inputs incorrectly blocked)
- Detection rate (malicious inputs correctly caught)
- Latency impact on user experience
- Ease of implementation and maintenance
- Coverage across attack types
We'd like to explore your experience with LLM security practices in a bit more depth. An AI moderator will ask a couple of follow-up questions based on your earlier responses.
How many years of professional software development experience do you have?
- Less than 1 year
- 1–3 years
- 4–6 years
- 7–10 years
- More than 10 years
Thank you for completing this survey! Your responses will contribute to a better understanding of LLM security practices across the developer community and help improve secure development guidance.
Which of the following best describes your current involvement with LLM-integrated features?
- I currently build or maintain LLM-integrated features
- I am planning to integrate LLMs in the next 6 months
- I am not currently working with LLMs
How well-prepared is your team or organization to defend against prompt injection attacks on your LLM-integrated applications?
Rank the following LLM security concerns from highest to lowest priority for your work.
- Direct prompt injection via user input
- Indirect prompt injection via external content
- Data leakage via prompts or responses
- Over-permissive tool or agent actions
- Model override / jailbreak to bypass policies
How often does your team evaluate for prompt injection or jailbreak risks?
- Weekly or more often
- Every 2–3 weeks
- Monthly
- Quarterly
- Less often or never
Briefly describe the incident and how it was handled. Please omit any sensitive or proprietary information.
What is your biggest obstacle to managing prompt injection risk today?
Based on your responses in this survey, please share any additional thoughts or experiences related to LLM security and prompt injection that we haven't covered. (Optional)
Approximately how many employees are in your organization?
- 1–10
- 11–50
- 51–200
- 201–1,000
- 1,001–5,000
- 5,001+
Where have you learned about prompt injection risks and mitigations? Select all that apply.
- Vendor or framework documentation
- OWASP Top 10 for LLM Applications
- Academic papers or preprints
- Security blogs or newsletters
- Conference talks or workshops
- Internal training or peer guidance
- Social media or forums
- I have not sought out information on this topic
Which methods does your team use to test for prompt injection vulnerabilities? Select all that apply.
- Adversarial red teaming by engineers
- Automated evaluation suites or checklists
- Unit or integration tests for prompts
- Canary or honeytoken detection
- Shadow deployment with monitoring and alerts
- External penetration testing
- We do not currently test for this
Where are you primarily located?
- Africa
- Asia
- Europe
- Latin America
- Middle East
- North America
- Oceania
What is your team's default response policy when LLM input may be unsafe?
- Allow but sanitize or validate content
- Block and ask the user for clarification
- Escalate to human review
- Varies by context or risk level
- Not sure
Which industry best describes your organization?
- Technology / Software
- Finance / Banking
- Healthcare
- Retail / E-commerce
- Manufacturing
- Education
- Government / Nonprofit
- Other (please specify)
Which types of tools or platforms does your team use to mitigate prompt injection risks? Select all that apply.
- LLM gateway or proxy with policy enforcement
- Content moderation or safety APIs
- Vector database with filtering or access controls
- Open-source guardrails libraries (e.g., Guardrails AI, NeMo Guardrails)
- Cloud provider built-in safety features
- Custom internal middleware or services
- None
含まれる機能
AIによる深掘り
自由回答に合わせてAIが追加で質問し、固定のフォームでは拾えない具体的な内容を引き出します。
注意確認設問
急いだ回答や質の低い回答者を除外する仕組みを標準で備えています。
AIが作成する設問文
文言、設問の順序、条件分岐をAIが調査の目的に合わせて作成します。
自動レポート
回答が集まると、テーマ、引用、わかりやすい要約が自動で作成されます。
他ツールとの比較
ほかのアンケートツールで最も近いテンプレートを調べました。それぞれの優れている点と、このテンプレートがさらに踏み込んでいる点をまとめています。
このテンプレートを選ぶ理由
- Purpose-built for LLM prompt injection risk, covering awareness, current mitigations (input validation, output filtering, sandboxing, etc.), testing cadence, and tooling adoption specific to LLM-integrated features.
- Includes an AI follow-up interview segment that can adaptively probe on reported incidents or gaps, rather than relying solely on fixed-choice questions.
- Combines quantitative signals (opinion scales on confidence/preparedness, ranked prioritization of security concerns and metrics) with open-text incident descriptions and obstacle narratives for richer qualitative context.
- Captures organizational context (role, team involvement, org size, industry, experience) alongside technical practice questions, enabling segmented analysis of prompt injection readiness across engineering teams.
Jotform
Security Awareness Survey Form TemplateA general information-security awareness survey template, not tailored to LLM or prompt injection risks. It's a ready-to-field static form built for broad security topics like phishing and password hygiene rather than AI-specific threat vectors. Useful as a starting point but requires heavy customization to address LLM application security.
優れている点
- Ready-to-use drag-and-drop form builder for quick deployment
- Broad applicability across general security awareness topics
- Likely integrates with Jotform's wider form/workflow ecosystem
物足りない点
- No LLM or prompt injection-specific question content
- Static question set with no adaptive AI follow-up interviewing
- No automated per-response quality scoring or transparent AI prompt methodology
SurveyMonkey
Security Awareness Survey TemplateA generic security awareness survey template aimed at general workforce training topics, not LLM-integrated engineering teams or prompt injection specifically. It offers a standard fixed-question format typical of SurveyMonkey's template library. Teams would need to build custom questions from scratch to capture LLM security practices.
優れている点
- Established survey platform with strong distribution and reporting tools
- Simple template structure for fast setup
- Benchmarking and analytics features typical of SurveyMonkey's suite
物足りない点
- No content addressing prompt injection, jailbreaks, or LLM-specific mitigations
- Fixed-form design lacks adaptive or voice AI interviewing capability
- No transparent AI prompt disclosure or automated quality scoring per response
よくあるご質問
「LLM Prompt Injection Awareness & Mitigation Practices Survey」テンプレートにはどのような設問が含まれていますか?
すぐに使える設問が24問含まれており、最初の設問は次のとおりです:「Welcome! Thank you for participating in this survey about your experiences with LLM application development and security…」・「Which area best describes your primary role?」・「How confident are you in your personal understanding of prompt injection risks and mitigations?」。すべての設問は上でプレビューでき、自由に編集できます。
このアンケートの回答にはどのくらい時間がかかりますか?
回答者は通常、24問を約11分で回答し終えます。
テンプレートは編集できますか?
はい。公開前であれば、すべての設問、選択肢、順序を編集できます。設問の追加や削除のほか、調査の目的に合わせた作り直しをAIエディターに依頼することもできます。
このテンプレートは無料で使えますか?
はい。エディターで開けば、すぐに編集を始められます。お試しにアカウントは不要で、無料プランでアンケートを公開できます。
公開の準備はできましたか?
このテンプレートをエディターで開いてみてください。最初の回答者が目にする前に、すべてを自由に変更できます。
関連テンプレート
似たテーマのほかの調査もご覧ください。