Prompt Injection Attack to Tool Selection in LLM Agents
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Shi, Jiawen, Yuan, Zenghui, Tie, Guiyao, Zhou, Pan, Gong, Neil Zhenqiang, Sun, Lichao |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
von: Shi, Jiawen, et al.
Veröffentlicht: (2024)
von: Shi, Jiawen, et al.
Veröffentlicht: (2024)
Poisoned-MRAG: Knowledge Poisoning Attacks to Multimodal Retrieval Augmented Generation
von: Liu, Yinuo, et al.
Veröffentlicht: (2025)
von: Liu, Yinuo, et al.
Veröffentlicht: (2025)
BadToken: Token-level Backdoor Attacks to Multi-modal Large Language Models
von: Yuan, Zenghui, et al.
Veröffentlicht: (2025)
von: Yuan, Zenghui, et al.
Veröffentlicht: (2025)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
von: Tie, Guiyao, et al.
Veröffentlicht: (2026)
von: Tie, Guiyao, et al.
Veröffentlicht: (2026)
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
von: Wang, Reachal, et al.
Veröffentlicht: (2025)
von: Wang, Reachal, et al.
Veröffentlicht: (2025)
Merge Hijacking: Backdoor Attacks to Model Merging of Large Language Models
von: Yuan, Zenghui, et al.
Veröffentlicht: (2025)
von: Yuan, Zenghui, et al.
Veröffentlicht: (2025)
DataSentinel: A Game-Theoretic Detection of Prompt Injection Attacks
von: Liu, Yupei, et al.
Veröffentlicht: (2025)
von: Liu, Yupei, et al.
Veröffentlicht: (2025)
A Critical Evaluation of Defenses against Prompt Injection Attacks
von: Jia, Yuqi, et al.
Veröffentlicht: (2025)
von: Jia, Yuqi, et al.
Veröffentlicht: (2025)
Virtual Context: Enhancing Jailbreak Attacks with Special Token Injection
von: Zhou, Yuqi, et al.
Veröffentlicht: (2024)
von: Zhou, Yuqi, et al.
Veröffentlicht: (2024)
Enhancing Prompt Injection Attacks to LLMs via Poisoning Alignment
von: Shao, Zedian, et al.
Veröffentlicht: (2024)
von: Shao, Zedian, et al.
Veröffentlicht: (2024)
Formalizing and Benchmarking Prompt Injection Attacks and Defenses
von: Liu, Yupei, et al.
Veröffentlicht: (2023)
von: Liu, Yupei, et al.
Veröffentlicht: (2023)
MalTool: Malicious Tool Attacks on LLM Agents
von: Hu, Yuepeng, et al.
Veröffentlicht: (2026)
von: Hu, Yuepeng, et al.
Veröffentlicht: (2026)
WAInjectBench: Benchmarking Prompt Injection Detections for Web Agents
von: Liu, Yinuo, et al.
Veröffentlicht: (2025)
von: Liu, Yinuo, et al.
Veröffentlicht: (2025)
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
von: Zhang, Mohan, et al.
Veröffentlicht: (2026)
von: Zhang, Mohan, et al.
Veröffentlicht: (2026)
PromptLocate: Localizing Prompt Injection Attacks
von: Jia, Yuqi, et al.
Veröffentlicht: (2025)
von: Jia, Yuqi, et al.
Veröffentlicht: (2025)
AlignSentinel: Alignment-Aware Detection of Prompt Injection Attacks
von: Jia, Yuqi, et al.
Veröffentlicht: (2026)
von: Jia, Yuqi, et al.
Veröffentlicht: (2026)
SecInfer: Preventing Prompt Injection via Inference-time Scaling
von: Liu, Yupei, et al.
Veröffentlicht: (2025)
von: Liu, Yupei, et al.
Veröffentlicht: (2025)
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
von: Zou, Wei, et al.
Veröffentlicht: (2025)
von: Zou, Wei, et al.
Veröffentlicht: (2025)
BadVLA: Towards Backdoor Attacks on Vision-Language-Action Models via Objective-Decoupled Optimization
von: Zhou, Xueyang, et al.
Veröffentlicht: (2025)
von: Zhou, Xueyang, et al.
Veröffentlicht: (2025)
AutoJailbreak: Exploring Jailbreak Attacks and Defenses through a Dependency Lens
von: Lu, Lin, et al.
Veröffentlicht: (2024)
von: Lu, Lin, et al.
Veröffentlicht: (2024)
Model Poisoning Attacks to Federated Learning via Multi-Round Consistency
von: Xie, Yueqi, et al.
Veröffentlicht: (2024)
von: Xie, Yueqi, et al.
Veröffentlicht: (2024)
WebSentinel: Detecting and Localizing Prompt Injection Attacks for Web Agents
von: Wang, Xilong, et al.
Veröffentlicht: (2026)
von: Wang, Xilong, et al.
Veröffentlicht: (2026)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
von: Wang, Yihan, et al.
Veröffentlicht: (2025)
von: Wang, Yihan, et al.
Veröffentlicht: (2025)
The Vulnerability of LLM Rankers to Prompt Injection Attacks
von: Yin, Yu, et al.
Veröffentlicht: (2026)
von: Yin, Yu, et al.
Veröffentlicht: (2026)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
von: Wang, Zhilong, et al.
Veröffentlicht: (2025)
von: Wang, Zhilong, et al.
Veröffentlicht: (2025)
Competitive Advantage Attacks to Decentralized Federated Learning
von: Jia, Yuqi, et al.
Veröffentlicht: (2023)
von: Jia, Yuqi, et al.
Veröffentlicht: (2023)
PINA: Prompt Injection Attack against Navigation Agents
von: Liu, Jiani, et al.
Veröffentlicht: (2026)
von: Liu, Jiani, et al.
Veröffentlicht: (2026)
Evaluating LLM-based Personal Information Extraction and Countermeasures
von: Liu, Yupei, et al.
Veröffentlicht: (2024)
von: Liu, Yupei, et al.
Veröffentlicht: (2024)
Is Your Prompt Safe? Investigating Prompt Injection Attacks Against Open-Source LLMs
von: Wang, Jiawen, et al.
Veröffentlicht: (2025)
von: Wang, Jiawen, et al.
Veröffentlicht: (2025)
Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
ToolTweak: An Attack on Tool Selection in LLM-based Agents
von: Sneh, Jonathan, et al.
Veröffentlicht: (2025)
von: Sneh, Jonathan, et al.
Veröffentlicht: (2025)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
von: He, Yu, et al.
Veröffentlicht: (2026)
von: He, Yu, et al.
Veröffentlicht: (2026)
A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
Can Indirect Prompt Injection Attacks Be Detected and Removed?
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?
von: Pedro, Rodrigo, et al.
Veröffentlicht: (2023)
von: Pedro, Rodrigo, et al.
Veröffentlicht: (2023)
Backdoor-Powered Prompt Injection Attacks Nullify Defense Methods
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
PromptShield: Deployable Detection for Prompt Injection Attacks
von: Jacob, Dennis, et al.
Veröffentlicht: (2025)
von: Jacob, Dennis, et al.
Veröffentlicht: (2025)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
von: Zhao, Wei, et al.
Veröffentlicht: (2026)
von: Zhao, Wei, et al.
Veröffentlicht: (2026)
Securing AI Agents Against Prompt Injection Attacks
von: Ramakrishnan, Badrinath, et al.
Veröffentlicht: (2025)
von: Ramakrishnan, Badrinath, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
von: Shi, Jiawen, et al.
Veröffentlicht: (2024) -
Poisoned-MRAG: Knowledge Poisoning Attacks to Multimodal Retrieval Augmented Generation
von: Liu, Yinuo, et al.
Veröffentlicht: (2025) -
BadToken: Token-level Backdoor Attacks to Multi-modal Large Language Models
von: Yuan, Zenghui, et al.
Veröffentlicht: (2025) -
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
von: Tie, Guiyao, et al.
Veröffentlicht: (2026) -
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
von: Wang, Reachal, et al.
Veröffentlicht: (2025)