MIP against Agent: Malicious Image Patches Hijacking Multimodal OS Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Aichberger, Lukas, Paren, Alasdair, Li, Guohao, Torr, Philip, Gal, Yarin, Bibi, Adel |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
ToolTweak: An Attack on Tool Selection in LLM-based Agents
by: Sneh, Jonathan, et al.
Published: (2025)
by: Sneh, Jonathan, et al.
Published: (2025)
Shh, don't say that! Domain Certification in LLMs
by: Emde, Cornelius, et al.
Published: (2025)
by: Emde, Cornelius, et al.
Published: (2025)
UDora: A Unified Red Teaming Framework against LLM Agents by Dynamically Hijacking Their Own Reasoning
by: Zhang, Jiawei, et al.
Published: (2025)
by: Zhang, Jiawei, et al.
Published: (2025)
Vera Verto: Multimodal Hijacking Attack
by: Zhang, Minxing, et al.
Published: (2024)
by: Zhang, Minxing, et al.
Published: (2024)
Multi-Agent Systems Execute Arbitrary Malicious Code
by: Triedman, Harold, et al.
Published: (2025)
by: Triedman, Harold, et al.
Published: (2025)
MAIDS: Malicious Agent Identification-based Data Security Model for Cloud Environments
by: Gupta, Kishu, et al.
Published: (2024)
by: Gupta, Kishu, et al.
Published: (2024)
CHAI: Command Hijacking against embodied AI
by: Burbano, Luis, et al.
Published: (2025)
by: Burbano, Luis, et al.
Published: (2025)
VLMGuard: Defending VLMs against Malicious Prompts via Unlabeled Data
by: Du, Xuefeng, et al.
Published: (2024)
by: Du, Xuefeng, et al.
Published: (2024)
RobPI: Robust Private Inference against Malicious Client
by: Xue, Jiaqi, et al.
Published: (2026)
by: Xue, Jiaqi, et al.
Published: (2026)
Model Hijacking Attack in Federated Learning
by: Li, Zheng, et al.
Published: (2024)
by: Li, Zheng, et al.
Published: (2024)
Detecting Malicious AI Agents Through Simulated Interactions
by: Pi, Yulu, et al.
Published: (2025)
by: Pi, Yulu, et al.
Published: (2025)
Breaking and Fixing Defenses Against Control-Flow Hijacking in Multi-Agent Systems
by: Jha, Rishi, et al.
Published: (2025)
by: Jha, Rishi, et al.
Published: (2025)
Malicious Internet Entity Detection Using Local Graph Inference
by: Mandlik, Simon, et al.
Published: (2024)
by: Mandlik, Simon, et al.
Published: (2024)
Osmosis Distillation: Model Hijacking with the Fewest Samples
by: Shi, Yuchen, et al.
Published: (2026)
by: Shi, Yuchen, et al.
Published: (2026)
Beyond Crash: Hijacking Your Autonomous Vehicle for Fun and Profit
by: Sun, Qi, et al.
Published: (2026)
by: Sun, Qi, et al.
Published: (2026)
Design Patterns for Securing LLM Agents against Prompt Injections
by: Beurer-Kellner, Luca, et al.
Published: (2025)
by: Beurer-Kellner, Luca, et al.
Published: (2025)
Fundamental Limitations in Pointwise Defences of LLM Finetuning APIs
by: Davies, Xander, et al.
Published: (2025)
by: Davies, Xander, et al.
Published: (2025)
FuncPoison: Poisoning Function Library to Hijack Multi-agent Autonomous Driving Systems
by: Long, Yuzhen, et al.
Published: (2025)
by: Long, Yuzhen, et al.
Published: (2025)
OMNI-LEAK: Orchestrator Multi-Agent Network Induced Data Leakage
by: Naik, Akshat, et al.
Published: (2026)
by: Naik, Akshat, et al.
Published: (2026)
Image Hijacks: Adversarial Images can Control Generative Models at Runtime
by: Bailey, Luke, et al.
Published: (2023)
by: Bailey, Luke, et al.
Published: (2023)
Moshi Moshi? A Model Selection Hijacking Adversarial Attack
by: Petrucci, Riccardo, et al.
Published: (2025)
by: Petrucci, Riccardo, et al.
Published: (2025)
GasTrace: Detecting Sandwich Attack Malicious Accounts in Ethereum
by: Liu, Zekai, et al.
Published: (2024)
by: Liu, Zekai, et al.
Published: (2024)
AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning Models
by: Liang, Jiacheng, et al.
Published: (2025)
by: Liang, Jiacheng, et al.
Published: (2025)
ML Study of MaliciousTransactions in Ethereum
by: Katz, Natan
Published: (2024)
by: Katz, Natan
Published: (2024)
Empirical Analysis of Large Vision-Language Models against Goal Hijacking via Visual Prompt Injection
by: Kimura, Subaru, et al.
Published: (2024)
by: Kimura, Subaru, et al.
Published: (2024)
AIJack: Let's Hijack AI! Security and Privacy Risk Simulator for Machine Learning
by: Takahashi, Hideaki
Published: (2023)
by: Takahashi, Hideaki
Published: (2023)
ShieldAgent: Shielding Agents via Verifiable Safety Policy Reasoning
by: Chen, Zhaorun, et al.
Published: (2025)
by: Chen, Zhaorun, et al.
Published: (2025)
Continuous Multi-Task Pre-training for Malicious URL Detection and Webpage Classification
by: Li, Yujie, et al.
Published: (2024)
by: Li, Yujie, et al.
Published: (2024)
Trust Me, I Know This Function: Hijacking LLM Static Analysis using Bias
by: Bernstein, Shir, et al.
Published: (2025)
by: Bernstein, Shir, et al.
Published: (2025)
Your Agent Can Defend Itself against Backdoor Attacks
by: Changjiang, Li, et al.
Published: (2025)
by: Changjiang, Li, et al.
Published: (2025)
Evaluating Generalization Mechanisms in Autonomous Cyber Attack Agents
by: Lukáš, Ondřej, et al.
Published: (2026)
by: Lukáš, Ondřej, et al.
Published: (2026)
Toward More Generalized Malicious URL Detection Models
by: Tsai, YunDa, et al.
Published: (2022)
by: Tsai, YunDa, et al.
Published: (2022)
A New Dataset and Methodology for Malicious URL Classification
by: Schvartzman, Ilan, et al.
Published: (2024)
by: Schvartzman, Ilan, et al.
Published: (2024)
Exploiting Leaderboards for Large-Scale Distribution of Malicious Models
by: Suri, Anshuman, et al.
Published: (2025)
by: Suri, Anshuman, et al.
Published: (2025)
Towards Quantum Machine Learning for Malicious Code Analysis
by: Lopez, Jesus, et al.
Published: (2025)
by: Lopez, Jesus, et al.
Published: (2025)
SplitOut: Out-of-the-Box Training-Hijacking Detection in Split Learning via Outlier Detection
by: Erdogan, Ege, et al.
Published: (2023)
by: Erdogan, Ege, et al.
Published: (2023)
Neutral Agent-based Adversarial Policy Learning against Deep Reinforcement Learning in Multi-party Open Systems
by: Peng, Qizhou, et al.
Published: (2025)
by: Peng, Qizhou, et al.
Published: (2025)
Hijack Vertical Federated Learning Models As One Party
by: Qiu, Pengyu, et al.
Published: (2022)
by: Qiu, Pengyu, et al.
Published: (2022)
Reasoning Introduces New Poisoning Attacks Yet Makes Them More Complicated
by: Foerster, Hanna, et al.
Published: (2025)
by: Foerster, Hanna, et al.
Published: (2025)
CleanBase: Detecting Malicious Documents in RAG Knowledge Databases
by: Jin, Weifei, et al.
Published: (2026)
by: Jin, Weifei, et al.
Published: (2026)
Similar Items
-
ToolTweak: An Attack on Tool Selection in LLM-based Agents
by: Sneh, Jonathan, et al.
Published: (2025) -
Shh, don't say that! Domain Certification in LLMs
by: Emde, Cornelius, et al.
Published: (2025) -
UDora: A Unified Red Teaming Framework against LLM Agents by Dynamically Hijacking Their Own Reasoning
by: Zhang, Jiawei, et al.
Published: (2025) -
Vera Verto: Multimodal Hijacking Attack
by: Zhang, Minxing, et al.
Published: (2024) -
Multi-Agent Systems Execute Arbitrary Malicious Code
by: Triedman, Harold, et al.
Published: (2025)