Prompt injection attacks usually aim to force a model to output harmful or attacker-chosen content. The ENDOPROMPT approach takes a different route: it degrades the model's performance on benign tasks without any need for harmful output. The authors argue that many existing attack objectives depend on task labels or predefined target responses, which can be a limitation.