AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Zhun, Siu, Vincent, Ye, Zhe, Shi, Tianneng, Nie, Yuzhou, Zhao, Xuandong, Wang, Chenguang, Guo, Wenbo, Song, Dawn
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918058637918208
author Wang, Zhun
Siu, Vincent
Ye, Zhe
Shi, Tianneng
Nie, Yuzhou
Zhao, Xuandong
Wang, Chenguang
Guo, Wenbo
Song, Dawn
author_facet Wang, Zhun
Siu, Vincent
Ye, Zhe
Shi, Tianneng
Nie, Yuzhou
Zhao, Xuandong
Wang, Chenguang
Guo, Wenbo
Song, Dawn
contents The strong planning and reasoning capabilities of Large Language Models (LLMs) have fostered the development of agent-based systems capable of leveraging external tools and interacting with increasingly complex environments. However, these powerful features also introduce a critical security risk: indirect prompt injection, a sophisticated attack vector that compromises the core of these agents, the LLM, by manipulating contextual information rather than direct user prompts. In this work, we propose a generic black-box fuzzing framework, AgentVigil, designed to automatically discover and exploit indirect prompt injection vulnerabilities across diverse LLM agents. Our approach starts by constructing a high-quality initial seed corpus, then employs a seed selection algorithm based on Monte Carlo Tree Search (MCTS) to iteratively refine inputs, thereby maximizing the likelihood of uncovering agent weaknesses. We evaluate AgentVigil on two public benchmarks, AgentDojo and VWA-adv, where it achieves 71% and 70% success rates against agents based on o3-mini and GPT-4o, respectively, nearly doubling the performance of baseline attacks. Moreover, AgentVigil exhibits strong transferability across unseen tasks and internal LLMs, as well as promising results against defenses. Beyond benchmark evaluations, we apply our attacks in real-world environments, successfully misleading agents to navigate to arbitrary URLs, including malicious sites.
format Preprint
id arxiv_https___arxiv_org_abs_2505_05849
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
Wang, Zhun
Siu, Vincent
Ye, Zhe
Shi, Tianneng
Nie, Yuzhou
Zhao, Xuandong
Wang, Chenguang
Guo, Wenbo
Song, Dawn
Cryptography and Security
Artificial Intelligence
The strong planning and reasoning capabilities of Large Language Models (LLMs) have fostered the development of agent-based systems capable of leveraging external tools and interacting with increasingly complex environments. However, these powerful features also introduce a critical security risk: indirect prompt injection, a sophisticated attack vector that compromises the core of these agents, the LLM, by manipulating contextual information rather than direct user prompts. In this work, we propose a generic black-box fuzzing framework, AgentVigil, designed to automatically discover and exploit indirect prompt injection vulnerabilities across diverse LLM agents. Our approach starts by constructing a high-quality initial seed corpus, then employs a seed selection algorithm based on Monte Carlo Tree Search (MCTS) to iteratively refine inputs, thereby maximizing the likelihood of uncovering agent weaknesses. We evaluate AgentVigil on two public benchmarks, AgentDojo and VWA-adv, where it achieves 71% and 70% success rates against agents based on o3-mini and GPT-4o, respectively, nearly doubling the performance of baseline attacks. Moreover, AgentVigil exhibits strong transferability across unseen tasks and internal LLMs, as well as promising results against defenses. Beyond benchmark evaluations, we apply our attacks in real-world environments, successfully misleading agents to navigate to arbitrary URLs, including malicious sites.
title AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.05849