Feedback-Guided Prompt Injection Defense in Retrieval-Augmented Text-to-Cypher Generation
Gergely Szlobodnyik · Analytics · 2026
Text-to-Cypher generator systems translate natural language questions into cypher queries, enabling intuitive interactions with graph databases such as Neo4j. Despite recent advancements in LLM-based cypher query generation, the vulnerability of the proposed methods – such as prompt injection attacks – are not discussed and addressed. In this paper, we introduce a robust Retrieval-Augmented Generation (RAG) architecture tailored specifically for Text-to-Cypher tasks, leveraging dense vector retrieval to enhance query generation accuracy. The proposed RAG architecture can efficiently support data access control and governance. In addition, we propose a feedback-loop based, self-adaptive agentic AI architecture employing Large Language Models (LLMs) for real-time validation and correction of generated queries. We create a systematic procedure for generating datasets specifically designed to assess prompt injection robustness. Comprehensive evaluations are conducted using a diverse set of LLMs, including GPT-4o, DeepSeek R1, Claude 3.5 Sonnet and Qwen 2.5 Coder 32B Instruct. Our evaluation results indicate substantial improvements in resiliency against prompt injection attacks.