AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery
Fuente:
arXiv
Saved in:
| Main Authors: | Wang, Haowei, Wang, Junjie, Jia, Xiaojun, Zhang, Rupeng, Li, Mingyang, Liu, Zhe, Liu, Yang, Wang, Qing |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation Systems
by: Wang, Haowei, et al.
Published: (2025)
by: Wang, Haowei, et al.
Published: (2025)
From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection
by: Wang, Haowei, et al.
Published: (2024)
by: Wang, Haowei, et al.
Published: (2024)
One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
by: Chang, Zhiyuan, et al.
Published: (2025)
by: Chang, Zhiyuan, et al.
Published: (2025)
Black-Box Skill Stealing Attack from Proprietary LLM Agents: An Empirical Study
by: Wang, Zihan, et al.
Published: (2026)
by: Wang, Zihan, et al.
Published: (2026)
PBI-Attack: Prior-Guided Bimodal Interactive Black-Box Jailbreak Attack for Toxicity Maximization
by: Cheng, Ruoxi, et al.
Published: (2024)
by: Cheng, Ruoxi, et al.
Published: (2024)
PolyJailbreak: Cross-Modal Jailbreaking Attacks on Black-Box Multimodal LLMs
by: Wang, Xinkai, et al.
Published: (2025)
by: Wang, Xinkai, et al.
Published: (2025)
CodePurify: Defend Backdoor Attacks on Neural Code Models via Entropy-based Purification
by: Mu, Fangwen, et al.
Published: (2024)
by: Mu, Fangwen, et al.
Published: (2024)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)
by: Zou, Wei, et al.
Published: (2026)
Play Guessing Game with LLM: Indirect Jailbreak Attack with Implicit Clues
by: Chang, Zhiyuan, et al.
Published: (2024)
by: Chang, Zhiyuan, et al.
Published: (2024)
How stealthy is stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World
by: Panebianco, Francesco, et al.
Published: (2025)
by: Panebianco, Francesco, et al.
Published: (2025)
Know Thy Enemy: Securing LLMs Against Prompt Injection via Diverse Data Synthesis and Instruction-Level Chain-of-Thought Learning
by: Chang, Zhiyuan, et al.
Published: (2026)
by: Chang, Zhiyuan, et al.
Published: (2026)
Black-Box Guardrail Reverse-engineering Attack
by: Yao, Hongwei, et al.
Published: (2025)
by: Yao, Hongwei, et al.
Published: (2025)
Transferable Hypergraph Attack via Injecting Nodes into Pivotal Hyperedges
by: He, Meixia, et al.
Published: (2025)
by: He, Meixia, et al.
Published: (2025)
WebSentinel: Detecting and Localizing Prompt Injection Attacks for Web Agents
by: Wang, Xilong, et al.
Published: (2026)
by: Wang, Xilong, et al.
Published: (2026)
Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System
by: Jiang, Ziyou, et al.
Published: (2025)
by: Jiang, Ziyou, et al.
Published: (2025)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
by: Wang, Zhun, et al.
Published: (2025)
by: Wang, Zhun, et al.
Published: (2025)
Adversarial Agents: Black-Box Evasion Attacks with Reinforcement Learning
by: Domico, Kyle, et al.
Published: (2025)
by: Domico, Kyle, et al.
Published: (2025)
ICL-EVADER: Zero-Query Black-Box Evasion Attacks on In-Context Learning and Their Defenses
by: He, Ningyuan, et al.
Published: (2026)
by: He, Ningyuan, et al.
Published: (2026)
Tricking Retrievers with Influential Tokens: An Efficient Black-Box Corpus Poisoning Attack
by: Wang, Cheng, et al.
Published: (2025)
by: Wang, Cheng, et al.
Published: (2025)
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
by: Yang, Ruozhao, et al.
Published: (2026)
by: Yang, Ruozhao, et al.
Published: (2026)
Lattice-Based Dynamic $k$-Times Anonymous Authentication with Attribute-Based Credentials
by: Song, Junjie, et al.
Published: (2025)
by: Song, Junjie, et al.
Published: (2025)
Black-Box Membership Inference Attack for LVLMs via Prior Knowledge-Calibrated Memory Probing
by: Yin, Jinhua, et al.
Published: (2025)
by: Yin, Jinhua, et al.
Published: (2025)
Enhanced MLLM Black-Box Jailbreaking Attacks and Defenses
by: Zhong, Xingwei, et al.
Published: (2025)
by: Zhong, Xingwei, et al.
Published: (2025)
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
by: Schmotz, David, et al.
Published: (2026)
by: Schmotz, David, et al.
Published: (2026)
OrchJail: Jailbreaking Tool-Calling Text-to-Image Agents by Orchestration-Guided Fuzzing
by: Chen, Jianming, et al.
Published: (2026)
by: Chen, Jianming, et al.
Published: (2026)
"Someone Hid It": Query-Agnostic Black-Box Attacks on LLM-Based Retrieval
by: Li, Jiate, et al.
Published: (2026)
by: Li, Jiate, et al.
Published: (2026)
Crabs: Consuming Resource via Auto-generation for LLM-DoS Attack under Black-box Settings
by: Zhang, Yuanhe, et al.
Published: (2024)
by: Zhang, Yuanhe, et al.
Published: (2024)
A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection Systems
by: Liu, Zixuan, et al.
Published: (2025)
by: Liu, Zixuan, et al.
Published: (2025)
WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
by: Chen, Yulin, et al.
Published: (2026)
by: Chen, Yulin, et al.
Published: (2026)
Distributional Black-Box Model Inversion Attack with Multi-Agent Reinforcement Learning
by: Bao, Huan, et al.
Published: (2024)
by: Bao, Huan, et al.
Published: (2024)
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
by: Pan, Yumingzhi, et al.
Published: (2025)
by: Pan, Yumingzhi, et al.
Published: (2025)
ComMark: Covert and Robust Black-Box Model Watermarking with Compressed Samples
by: Yang, Yunfei, et al.
Published: (2025)
by: Yang, Yunfei, et al.
Published: (2025)
Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable Confidence
by: Hong, Hanbin, et al.
Published: (2023)
by: Hong, Hanbin, et al.
Published: (2023)
Can Drift-Adaptive Malware Detectors Be Made Robust? Attacks and Defenses Under White-Box and Black-Box Threats
by: Li, Adrian Shuai, et al.
Published: (2026)
by: Li, Adrian Shuai, et al.
Published: (2026)
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
The Black-Box Simulation Barrier Persists in a Fully Quantum World
by: Chia, Nai-Hui, et al.
Published: (2024)
by: Chia, Nai-Hui, et al.
Published: (2024)
Jailbreaking Commercial Black-Box LLMs with Explicitly Harmful Prompts
by: Zhang, Chiyu, et al.
Published: (2025)
by: Zhang, Chiyu, et al.
Published: (2025)
Discovering New Shadow Patterns for Black-Box Attacks on Lane Detection of Autonomous Vehicles
by: MohajerAnsari, Pedram, et al.
Published: (2024)
by: MohajerAnsari, Pedram, et al.
Published: (2024)
SurvAttack: Black-Box Attack On Survival Models through Ontology-Informed EHR Perturbation
by: Kerdabadi, Mohsen Nayebi, et al.
Published: (2024)
by: Kerdabadi, Mohsen Nayebi, et al.
Published: (2024)
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
by: Wang, Reachal, et al.
Published: (2025)
by: Wang, Reachal, et al.
Published: (2025)
Similar Items
-
Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation Systems
by: Wang, Haowei, et al.
Published: (2025) -
From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection
by: Wang, Haowei, et al.
Published: (2024) -
One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
by: Chang, Zhiyuan, et al.
Published: (2025) -
Black-Box Skill Stealing Attack from Proprietary LLM Agents: An Empirical Study
by: Wang, Zihan, et al.
Published: (2026) -
PBI-Attack: Prior-Guided Bimodal Interactive Black-Box Jailbreak Attack for Toxicity Maximization
by: Cheng, Ruoxi, et al.
Published: (2024)