LLM Prompt Injection Awareness & Mitigation Practices Survey
Measures developer awareness of prompt injection threats, captures current security mitigation practices, and identifies gaps in LLM application defense. Designed for engineering teams building or evaluating LLM-integrated features.
Sample questions
A preview of what’s in the template. Every question is editable before you launch.
Which area best describes your primary role?
- Back-end engineering
- Front-end engineering
- Full-stack engineering
- Machine learning / data science
- DevOps / SRE
- Security engineering
- QA / Test automation
- Other (please specify)
How confident are you in your personal understanding of prompt injection risks and mitigations?
Which of the following threat vectors do you consider when designing or reviewing LLM features? Select all that apply.
- Prompt injection (malicious instructions in user input)
- Indirect prompt injection via external content sources
- Jailbreaks / model override of system policies
- Data exfiltration or leakage via prompts or responses
- Tool misuse or over-permissioned agent actions
- Training data poisoning
- Prompt leakage or system prompt version exposure
- None of these
Which of the following prompt injection mitigations has your team adopted? Select all that apply.
- Input validation and sanitization of user prompts
- System prompt hardening (e.g., instruction hierarchy, delimiters)
- Output filtering or content safety checks
- Role-based access controls for LLM tool/action permissions
- Monitoring and logging of LLM interactions
- Canary tokens or honeypots in system prompts
- Sandboxing or isolation of LLM execution environments
- None of these
- Not sure
In the last 6 months, have you encountered suspected prompt injection or jailbreak activity in your systems?
- Yes — confirmed incident
- Possibly — suspicious behavior, not confirmed
- No
Rank the following metrics by how much you prioritize them when evaluating prompt injection mitigations (top = highest priority).
- False positive rate (legitimate inputs incorrectly blocked)
- Detection rate (malicious inputs correctly caught)
- Latency impact on user experience
- Ease of implementation and maintenance
- Coverage across attack types
We'd like to explore your experience with LLM security practices in a bit more depth. An AI moderator will ask a couple of follow-up questions based on your earlier responses.
How many years of professional software development experience do you have?
- Less than 1 year
- 1–3 years
- 4–6 years
- 7–10 years
- More than 10 years
Thank you for completing this survey! Your responses will contribute to a better understanding of LLM security practices across the developer community and help improve secure development guidance.
Which of the following best describes your current involvement with LLM-integrated features?
- I currently build or maintain LLM-integrated features
- I am planning to integrate LLMs in the next 6 months
- I am not currently working with LLMs
How well-prepared is your team or organization to defend against prompt injection attacks on your LLM-integrated applications?
Rank the following LLM security concerns from highest to lowest priority for your work.
- Direct prompt injection via user input
- Indirect prompt injection via external content
- Data leakage via prompts or responses
- Over-permissive tool or agent actions
- Model override / jailbreak to bypass policies
How often does your team evaluate for prompt injection or jailbreak risks?
- Weekly or more often
- Every 2–3 weeks
- Monthly
- Quarterly
- Less often or never
Briefly describe the incident and how it was handled. Please omit any sensitive or proprietary information.
What is your biggest obstacle to managing prompt injection risk today?
Based on your responses in this survey, please share any additional thoughts or experiences related to LLM security and prompt injection that we haven't covered. (Optional)
Approximately how many employees are in your organization?
- 1–10
- 11–50
- 51–200
- 201–1,000
- 1,001–5,000
- 5,001+
Where have you learned about prompt injection risks and mitigations? Select all that apply.
- Vendor or framework documentation
- OWASP Top 10 for LLM Applications
- Academic papers or preprints
- Security blogs or newsletters
- Conference talks or workshops
- Internal training or peer guidance
- Social media or forums
- I have not sought out information on this topic
Which methods does your team use to test for prompt injection vulnerabilities? Select all that apply.
- Adversarial red teaming by engineers
- Automated evaluation suites or checklists
- Unit or integration tests for prompts
- Canary or honeytoken detection
- Shadow deployment with monitoring and alerts
- External penetration testing
- We do not currently test for this
Where are you primarily located?
- Africa
- Asia
- Europe
- Latin America
- Middle East
- North America
- Oceania
What is your team's default response policy when LLM input may be unsafe?
- Allow but sanitize or validate content
- Block and ask the user for clarification
- Escalate to human review
- Varies by context or risk level
- Not sure
Which industry best describes your organization?
- Technology / Software
- Finance / Banking
- Healthcare
- Retail / E-commerce
- Manufacturing
- Education
- Government / Nonprofit
- Other (please specify)
Which types of tools or platforms does your team use to mitigate prompt injection risks? Select all that apply.
- LLM gateway or proxy with policy enforcement
- Content moderation or safety APIs
- Vector database with filtering or access controls
- Open-source guardrails libraries (e.g., Guardrails AI, NeMo Guardrails)
- Cloud provider built-in safety features
- Custom internal middleware or services
- None
What’s included
AI follow-ups
Adaptive probes on open-ended answers that pull out detail a static form would miss.
Attention checks
Built-in safeguards against rushed answers and low-quality respondents.
AI-drafted copy
Wording, ordering, and branching written by the AI — tuned to your research goal.
Auto report
Themes, quotes, and a plain-English summary write themselves once responses come in.
How it compares
We reviewed the closest templates from other survey tools. Here’s what they do well — and where this template goes further.
Why this template
- Purpose-built for LLM prompt injection risk, covering awareness, current mitigations (input validation, output filtering, sandboxing, etc.), testing cadence, and tooling adoption specific to LLM-integrated features.
- Includes an AI follow-up interview segment that can adaptively probe on reported incidents or gaps, rather than relying solely on fixed-choice questions.
- Combines quantitative signals (opinion scales on confidence/preparedness, ranked prioritization of security concerns and metrics) with open-text incident descriptions and obstacle narratives for richer qualitative context.
- Captures organizational context (role, team involvement, org size, industry, experience) alongside technical practice questions, enabling segmented analysis of prompt injection readiness across engineering teams.
Jotform
Security Awareness Survey Form TemplateA general information-security awareness survey template, not tailored to LLM or prompt injection risks. It's a ready-to-field static form built for broad security topics like phishing and password hygiene rather than AI-specific threat vectors. Useful as a starting point but requires heavy customization to address LLM application security.
What it does well
- Ready-to-use drag-and-drop form builder for quick deployment
- Broad applicability across general security awareness topics
- Likely integrates with Jotform's wider form/workflow ecosystem
Where it falls short
- No LLM or prompt injection-specific question content
- Static question set with no adaptive AI follow-up interviewing
- No automated per-response quality scoring or transparent AI prompt methodology
SurveyMonkey
Security Awareness Survey TemplateA generic security awareness survey template aimed at general workforce training topics, not LLM-integrated engineering teams or prompt injection specifically. It offers a standard fixed-question format typical of SurveyMonkey's template library. Teams would need to build custom questions from scratch to capture LLM security practices.
What it does well
- Established survey platform with strong distribution and reporting tools
- Simple template structure for fast setup
- Benchmarking and analytics features typical of SurveyMonkey's suite
Where it falls short
- No content addressing prompt injection, jailbreaks, or LLM-specific mitigations
- Fixed-form design lacks adaptive or voice AI interviewing capability
- No transparent AI prompt disclosure or automated quality scoring per response
Ready to launch?
Open this template in the editor. Every part is yours to change before the first respondent sees it.
Related templates
More studies from the same category.
OpenTelemetry Adoption & Readiness Assessment
Measures developer familiarity, adoption stage, blockers, and rollout priorities for OpenTelemetry across engineering teams to inform instrumentation strategy and resource planning.
View templateOpen Source Contributor Experience & Governance Survey
Measures contribution path clarity, governance transparency, maintainer responsiveness, and improvement priorities for open-source projects. Designed for project maintainers seeking to improve contributor satisfaction and retention.
View templateDeveloper Open-Source License Compliance Experience Survey
Measures how developers navigate open-source license compliance, including confidence levels, tooling satisfaction, workflow clarity, and key barriers. Designed for engineering teams and developer-tool organizations seeking to improve compliance processes and SBOM adoption.
View templateObservability Stack ROI Assessment
Measures perceived return on investment from logs, metrics, tracing, and monitoring tools across DevOps and SRE teams, identifying high-impact areas for investment and key barriers to value realization.
View templateDeveloper Productivity & AI Tooling Adoption Survey
Measures developer productivity, AI coding tool adoption and barriers, code quality practices, and professional growth for engineering teams. Designed for 6–8 minute completion with branching logic for AI tool users vs. non-users.
View templateDeveloper Experience Survey: Docs, Samples & Events
Measures developer satisfaction and outcomes across documentation, code samples, and community events to surface actionable improvement priorities for developer relations and product teams.
View template