When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
Fuente:
arXiv
Saved in:
| Main Authors: | Kaya, Yigitcan, Landerer, Anton, Pletinckx, Stijn, Zimmermann, Michelle, Kruegel, Christopher, Vigna, Giovanni |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation
by: Roh, Eunjin, et al.
Published: (2025)
by: Roh, Eunjin, et al.
Published: (2025)
MalwarePT: A Binary-Level Foundation Model for Malware Analysis
by: Vasan, Saastha, et al.
Published: (2026)
by: Vasan, Saastha, et al.
Published: (2026)
From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs
by: Ullah, Saad, et al.
Published: (2025)
by: Ullah, Saad, et al.
Published: (2025)
Cybersecurity AI: Hacking the AI Hackers via Prompt Injection
by: Mayoral-Vilches, Víctor, et al.
Published: (2025)
by: Mayoral-Vilches, Víctor, et al.
Published: (2025)
Remote Keylogging Attacks in Multi-user VR Applications
by: Su, Zihao, et al.
Published: (2024)
by: Su, Zihao, et al.
Published: (2024)
Invisible Image Watermarks Are Provably Removable Using Generative AI
by: Zhao, Xuandong, et al.
Published: (2023)
by: Zhao, Xuandong, et al.
Published: (2023)
When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech
by: Zeng, Qingwen, et al.
Published: (2026)
by: Zeng, Qingwen, et al.
Published: (2026)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
by: Ghebremichael, Jonah, et al.
Published: (2026)
by: Ghebremichael, Jonah, et al.
Published: (2026)
Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels
by: Du, Chenghao, et al.
Published: (2025)
by: Du, Chenghao, et al.
Published: (2025)
Blockchain-Enhanced Framework for Secure Third-Party Vendor Risk Management and Vigilant Security Controls
by: Gupta, Deepti, et al.
Published: (2024)
by: Gupta, Deepti, et al.
Published: (2024)
Prompt Injection 2.0: Hybrid AI Threats
by: McHugh, Jeremy, et al.
Published: (2025)
by: McHugh, Jeremy, et al.
Published: (2025)
Are AI-assisted Development Tools Immune to Prompt Injection?
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
Securing AI Agents Against Prompt Injection Attacks
by: Ramakrishnan, Badrinath, et al.
Published: (2025)
by: Ramakrishnan, Badrinath, et al.
Published: (2025)
From Prompt Injections to SQL Injection Attacks: How Protected is Your LLM-Integrated Web Application?
by: Pedro, Rodrigo, et al.
Published: (2023)
by: Pedro, Rodrigo, et al.
Published: (2023)
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
by: Chia-Pei, et al.
Published: (2026)
by: Chia-Pei, et al.
Published: (2026)
TrojanPuzzle: Covertly Poisoning Code-Suggestion Models
by: Aghakhani, Hojjat, et al.
Published: (2023)
by: Aghakhani, Hojjat, et al.
Published: (2023)
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
by: Maloyan, Narek, et al.
Published: (2026)
by: Maloyan, Narek, et al.
Published: (2026)
When Your Reviewer is an LLM: Biases, Divergence, and Prompt Injection Risks in Peer Review
by: Zhu, Changjia, et al.
Published: (2025)
by: Zhu, Changjia, et al.
Published: (2025)
IDPFilter: Mitigating Interdependent Privacy Issues in Third-Party Apps
by: Liu, Shuaishuai, et al.
Published: (2024)
by: Liu, Shuaishuai, et al.
Published: (2024)
WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
by: Chen, Yulin, et al.
Published: (2026)
by: Chen, Yulin, et al.
Published: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Browsing without Third-Party Cookies: What Do You See?
by: Lin, Maxwell, et al.
Published: (2024)
by: Lin, Maxwell, et al.
Published: (2024)
Who's Watching You Zoom? Investigating Privacy of Third-Party Zoom Apps
by: Goenka, Saharsh, et al.
Published: (2025)
by: Goenka, Saharsh, et al.
Published: (2025)
MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties
by: Chen, Guoxing, et al.
Published: (2020)
by: Chen, Guoxing, et al.
Published: (2020)
Design and Implementation of a Secure RAG-Enhanced AI Chatbot for Smart Tourism Customer Service: Defending Against Prompt Injection Attacks -- A Case Study of Hsinchu, Taiwan
by: Shih, Yu-Kai, et al.
Published: (2025)
by: Shih, Yu-Kai, et al.
Published: (2025)
AI Agents May Always Fall for Prompt Injections
by: Abdelnabi, Sahar, et al.
Published: (2026)
by: Abdelnabi, Sahar, et al.
Published: (2026)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
by: Zhu, Kaijie, et al.
Published: (2025)
by: Zhu, Kaijie, et al.
Published: (2025)
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
by: Yang, Ruozhao, et al.
Published: (2026)
by: Yang, Ruozhao, et al.
Published: (2026)
When RAG Chatbots Expose Their Backend: An Anonymized Case Study of Privacy and Security Risks in Patient-Facing Medical AI
by: Madrid-García, Alfredo, et al.
Published: (2026)
by: Madrid-García, Alfredo, et al.
Published: (2026)
DevOps-Gym: Benchmarking AI Agents in Software DevOps Cycle
by: Tang, Yuheng, et al.
Published: (2026)
by: Tang, Yuheng, et al.
Published: (2026)
Assessing Privacy Compliance of Android Third-Party SDKs
by: Meng, Mark Huasong, et al.
Published: (2024)
by: Meng, Mark Huasong, et al.
Published: (2024)
WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
by: Evtimov, Ivan, et al.
Published: (2025)
by: Evtimov, Ivan, et al.
Published: (2025)
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections
by: Cao, Tri, et al.
Published: (2026)
by: Cao, Tri, et al.
Published: (2026)
Assessing Prompt Injection Risks in 200+ Custom GPTs
by: Yu, Jiahao, et al.
Published: (2023)
by: Yu, Jiahao, et al.
Published: (2023)
PromptShield: Deployable Detection for Prompt Injection Attacks
by: Jacob, Dennis, et al.
Published: (2025)
by: Jacob, Dennis, et al.
Published: (2025)
ML-Based Behavioral Malware Detection Is Far From a Solved Problem
by: Kaya, Yigitcan, et al.
Published: (2024)
by: Kaya, Yigitcan, et al.
Published: (2024)
Toward Trustworthy Agentic AI: A Multimodal Framework for Preventing Prompt Injection Attacks
by: Syed, Toqeer Ali, et al.
Published: (2025)
by: Syed, Toqeer Ali, et al.
Published: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
by: Ferrag, Mohamed Amine, et al.
Published: (2025)
by: Ferrag, Mohamed Amine, et al.
Published: (2025)
Like Oil and Water: Group Robustness Methods and Poisoning Defenses May Be at Odds
by: Panaitescu-Liess, Michael-Andrei, et al.
Published: (2025)
by: Panaitescu-Liess, Michael-Andrei, et al.
Published: (2025)
Trust No AI: Prompt Injection Along The CIA Security Triad
by: Rehberger, Johann
Published: (2024)
by: Rehberger, Johann
Published: (2024)
Similar Items
-
MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation
by: Roh, Eunjin, et al.
Published: (2025) -
MalwarePT: A Binary-Level Foundation Model for Malware Analysis
by: Vasan, Saastha, et al.
Published: (2026) -
From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs
by: Ullah, Saad, et al.
Published: (2025) -
Cybersecurity AI: Hacking the AI Hackers via Prompt Injection
by: Mayoral-Vilches, Víctor, et al.
Published: (2025) -
Remote Keylogging Attacks in Multi-user VR Applications
by: Su, Zihao, et al.
Published: (2024)