Can the content an LLM judge is grading manipulate its verdict?

Yes. A 2025 study testing prompt-injection attacks on LLM-as-judge systems found that appending a crafted suffix to one of two responses being compared swayed the judge’s final verdict the attacker’s way more than 30% of the time; a second attack aimed at corrupting the judge’s stated reasoning instead of the verdict worked too, but at roughly half that rate, in the mid-teens percent. The judge reads the content it’s grading as part of its own prompt, so nothing structurally separates the text under evaluation from the instructions the judge follows. That matters most for a judge grading production traffic rather than a fixed eval set, because production content, a user’s message, a retrieved document, a tool’s result, is exactly the content an attacker can shape. The mitigation is the same one prompt injection gets everywhere: treat graded content as untrusted input rather than a trusted signal, and don’t let one judge call stand as the only check on a trace where the stakes are real.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y