Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous
Fuente:
arXiv
Saved in:
| Main Authors: | Nassi, Ben, Cohen, Stav, Yair, Or |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
by: Cohen, Stav, et al.
Published: (2024)
by: Cohen, Stav, et al.
Published: (2024)
Unleashing Worms and Extracting Data: Escalating the Outcome of Attacks against RAG-based Inference in Scale and Severity Using Jailbreaking
by: Cohen, Stav, et al.
Published: (2024)
by: Cohen, Stav, et al.
Published: (2024)
A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares
by: Cohen, Stav, et al.
Published: (2024)
by: Cohen, Stav, et al.
Published: (2024)
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
by: Brodt, Oleg, et al.
Published: (2026)
by: Brodt, Oleg, et al.
Published: (2026)
Injection Attacks Against End-to-End Encrypted Applications
by: Fábrega, Andrés, et al.
Published: (2024)
by: Fábrega, Andrés, et al.
Published: (2024)
Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
by: Zhong, Yinan, et al.
Published: (2025)
by: Zhong, Yinan, et al.
Published: (2025)
Detection and Defense Against Prominent Attacks on Preconditioned LLM-Integrated Virtual Assistants
by: Chan, Chun Fai, et al.
Published: (2024)
by: Chan, Chun Fai, et al.
Published: (2024)
Exploiting Leakage in Password Managers via Injection Attacks
by: Fábrega, Andrés, et al.
Published: (2024)
by: Fábrega, Andrés, et al.
Published: (2024)
All You Need Is A Fuzzing Brain: An LLM-Powered System for Automated Vulnerability Detection and Patching
by: Sheng, Ze, et al.
Published: (2025)
by: Sheng, Ze, et al.
Published: (2025)
Security Steerability is All You Need
by: Hazan, Itay, et al.
Published: (2025)
by: Hazan, Itay, et al.
Published: (2025)
Confidence Is All You Need for MI Attacks
by: Sinha, Abhishek, et al.
Published: (2023)
by: Sinha, Abhishek, et al.
Published: (2023)
Is Difficulty Calibration All We Need? Towards More Practical Membership Inference Attacks
by: He, Yu, et al.
Published: (2024)
by: He, Yu, et al.
Published: (2024)
Poison Attacks and Adversarial Prompts Against an Informed University Virtual Assistant
by: Fernandez, Ivan A., et al.
Published: (2024)
by: Fernandez, Ivan A., et al.
Published: (2024)
Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?
by: Bhagwatkar, Rishika, et al.
Published: (2025)
by: Bhagwatkar, Rishika, et al.
Published: (2025)
Lightweight Countermeasures Against Static Power Side-Channel Attacks
by: Bhandari, Jitendra, et al.
Published: (2024)
by: Bhandari, Jitendra, et al.
Published: (2024)
Buffer is All You Need: Defending Federated Learning against Backdoor Attacks under Non-iids via Buffering
by: Lyu, Xingyu, et al.
Published: (2025)
by: Lyu, Xingyu, et al.
Published: (2025)
Select Me! When You Need a Tool: A Black-box Text Attack on Tool Selection
by: Chen, Liuji, et al.
Published: (2025)
by: Chen, Liuji, et al.
Published: (2025)
When Safe Models Merge into Danger: Exploiting Latent Vulnerabilities in LLM Fusion
by: Li, Jiaqing, et al.
Published: (2026)
by: Li, Jiaqing, et al.
Published: (2026)
The Invitation Trap: Proactive Availability Backdoor in LLMs via Conversational Induction
by: Wang, He, et al.
Published: (2026)
by: Wang, He, et al.
Published: (2026)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
by: Wang, Yihan, et al.
Published: (2025)
by: Wang, Yihan, et al.
Published: (2025)
CaFA: Cost-aware, Feasible Attacks With Database Constraints Against Neural Tabular Classifiers
by: Ben-Tov, Matan, et al.
Published: (2025)
by: Ben-Tov, Matan, et al.
Published: (2025)
Ain't How You Deploy: An Analysis of BGP Security Policies Performance Against Various Attack Scenarios with Differing Deployment Strategies
by: Barrett, Seth, et al.
Published: (2024)
by: Barrett, Seth, et al.
Published: (2024)
Cuckoo Attack: Stealthy and Persistent Attacks Against AI-IDE
by: Liu, Xinpeng, et al.
Published: (2025)
by: Liu, Xinpeng, et al.
Published: (2025)
Defense Against Prompt Injection Attack by Leveraging Attack Techniques
by: Chen, Yulin, et al.
Published: (2024)
by: Chen, Yulin, et al.
Published: (2024)
Physical and Software Based Fault Injection Attacks Against TEEs in Mobile Devices: A Systemisation of Knowledge
by: Joy, Aaron, et al.
Published: (2024)
by: Joy, Aaron, et al.
Published: (2024)
SUAD: Solid-Channel Ultrasound Injection Attack and Defense to Voice Assistants
by: Liu, Chao, et al.
Published: (2025)
by: Liu, Chao, et al.
Published: (2025)
UAV Resilience Against Stealthy Attacks
by: Amorim, Arthur, et al.
Published: (2025)
by: Amorim, Arthur, et al.
Published: (2025)
Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
by: Zhan, Qiusi, et al.
Published: (2025)
by: Zhan, Qiusi, et al.
Published: (2025)
AttackPilot: Autonomous Inference Attacks Against ML Services With LLM-Based Agents
by: Wu, Yixin, et al.
Published: (2025)
by: Wu, Yixin, et al.
Published: (2025)
An Assessment of the Overlooked Dangers of Template Engines
by: Pisu, Lorenzo, et al.
Published: (2024)
by: Pisu, Lorenzo, et al.
Published: (2024)
SecureLearn -- An Attack-agnostic Defense for Multiclass Machine Learning Against Data Poisoning Attacks
by: Paracha, Anum, et al.
Published: (2025)
by: Paracha, Anum, et al.
Published: (2025)
Attacks and Defenses Against LLM Fingerprinting
by: Kurian, Kevin, et al.
Published: (2025)
by: Kurian, Kevin, et al.
Published: (2025)
Data Reconstruction: When You See It and When You Don't
by: Cohen, Edith, et al.
Published: (2024)
by: Cohen, Edith, et al.
Published: (2024)
Smart Privacy Policy Assistant: An LLM-Powered System for Transparent and Actionable Privacy Notices
by: Kalvakuntla, Sriharshini, et al.
Published: (2026)
by: Kalvakuntla, Sriharshini, et al.
Published: (2026)
Enhancing LLM Watermark Resilience Against Both Scrubbing and Spoofing Attacks
by: Shen, Huanming, et al.
Published: (2025)
by: Shen, Huanming, et al.
Published: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
by: Wang, Zhilong, et al.
Published: (2025)
by: Wang, Zhilong, et al.
Published: (2025)
Improving LLM Outputs Against Jailbreak Attacks with Expert Model Integration
by: Tsmindashvili, Tatia, et al.
Published: (2025)
by: Tsmindashvili, Tatia, et al.
Published: (2025)
Defending LLM Watermarking Against Spoofing Attacks with Contrastive Representation Learning
by: An, Li, et al.
Published: (2025)
by: An, Li, et al.
Published: (2025)
Reformulation is All You Need: Addressing Malicious Text Features in DNNs
by: Jiang, Yi, et al.
Published: (2025)
by: Jiang, Yi, et al.
Published: (2025)
Load-Altering Attacks Against Power Grids: A Case Study Using the GB-36 Bus System Open Dataset
by: Maksud, Syed Irtiza, et al.
Published: (2025)
by: Maksud, Syed Irtiza, et al.
Published: (2025)
Similar Items
-
Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
by: Cohen, Stav, et al.
Published: (2024) -
Unleashing Worms and Extracting Data: Escalating the Outcome of Attacks against RAG-based Inference in Scale and Severity Using Jailbreaking
by: Cohen, Stav, et al.
Published: (2024) -
A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares
by: Cohen, Stav, et al.
Published: (2024) -
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
by: Brodt, Oleg, et al.
Published: (2026) -
Injection Attacks Against End-to-End Encrypted Applications
by: Fábrega, Andrés, et al.
Published: (2024)