Can the content an LLM judge is grading manipulate its verdict?
Yes. A 2025 study testing prompt-injection attacks on LLM-as-judge systems found that appending a crafted suffix to one of two responses being compared swayed the judge’s final verdict the attacker’s way more than 30% of the time; a second attack aimed at corrupting the judge’s stated reasoning instead of the verdict worked too, but at roughly half that rate, in the mid-teens percent. The judge reads the content it’s grading as part of its own prompt, so nothing structurally separates the text under evaluation from the instructions the judge follows. That matters most for a judge grading production traffic rather than a fixed eval set, because production content, a user’s message, a retrieved document, a tool’s result, is exactly the content an attacker can shape. The mitigation is the same one prompt injection gets everywhere: treat graded content as untrusted input rather than a trusted signal, and don’t let one judge call stand as the only check on a trace where the stakes are real.