An attack where adversarial input tricks a model into ignoring its instructions and following new ones instead.