Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
Fuente:
arXiv
Guardado en:
| Autores principales: | Yang, Xianglin, He, Yufei, Ji, Shuo, Hooi, Bryan, Dong, Jin Song |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges
por: Yang, Xianglin, et al.
Publicado: (2026)
por: Yang, Xianglin, et al.
Publicado: (2026)
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections
por: Cao, Tri, et al.
Publicado: (2026)
por: Cao, Tri, et al.
Publicado: (2026)
VPI-Bench: Visual Prompt Injection Attacks for Computer-Use Agents
por: Cao, Tri, et al.
Publicado: (2025)
por: Cao, Tri, et al.
Publicado: (2025)
Proteus: A Self-Evolving Red Team for Agent Skill Ecosystems
por: Zhou, Zhaojiacheng
Publicado: (2026)
por: Zhou, Zhaojiacheng
Publicado: (2026)
OEP: Poisoning Self-Evolving LLM Agents via Locally Correct but Non-Transferable Experiences
por: Wang, Kaixiang, et al.
Publicado: (2026)
por: Wang, Kaixiang, et al.
Publicado: (2026)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
por: Wang, Zhun, et al.
Publicado: (2025)
por: Wang, Zhun, et al.
Publicado: (2025)
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
por: Srivastava, Saksham Sahai, et al.
Publicado: (2025)
por: Srivastava, Saksham Sahai, et al.
Publicado: (2025)
VIGIL: Defending LLM Agents Against Tool Stream Injection via Verify-Before-Commit
por: Lin, Junda, et al.
Publicado: (2026)
por: Lin, Junda, et al.
Publicado: (2026)
Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
por: Johnson, Sam, et al.
Publicado: (2025)
por: Johnson, Sam, et al.
Publicado: (2025)
AgentTypo: Adaptive Typographic Prompt Injection Attacks against Black-box Multimodal Agents
por: Li, Yanjie, et al.
Publicado: (2025)
por: Li, Yanjie, et al.
Publicado: (2025)
RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
por: Zhong, Peter Yong, et al.
Publicado: (2025)
por: Zhong, Peter Yong, et al.
Publicado: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
por: Wang, Zhilong, et al.
Publicado: (2025)
por: Wang, Zhilong, et al.
Publicado: (2025)
ICON: Indirect Prompt Injection Defense for Agents based on Inference-Time Correction
por: Wang, Che, et al.
Publicado: (2026)
por: Wang, Che, et al.
Publicado: (2026)
LLM-enabled Applications Require System-Level Threat Monitoring
por: Zhang, Yedi, et al.
Publicado: (2026)
por: Zhang, Yedi, et al.
Publicado: (2026)
Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning
por: Yang, Xianglin, et al.
Publicado: (2025)
por: Yang, Xianglin, et al.
Publicado: (2025)
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
por: Sehwag, Udari Madhushani, et al.
Publicado: (2026)
por: Sehwag, Udari Madhushani, et al.
Publicado: (2026)
DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
por: Li, Hao, et al.
Publicado: (2025)
por: Li, Hao, et al.
Publicado: (2025)
AIRGuard: Guarding Agent Actions with Runtime Authority Control
por: Qin, Suliu, et al.
Publicado: (2026)
por: Qin, Suliu, et al.
Publicado: (2026)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM Agent
por: Ning, Liang-bo, et al.
Publicado: (2025)
por: Ning, Liang-bo, et al.
Publicado: (2025)
A Framework for Formalizing LLM Agent Security
por: Siu, Vincent, et al.
Publicado: (2026)
por: Siu, Vincent, et al.
Publicado: (2026)
CyberEvolver: Structured Self-Evolution for Cybersecurity Agents On the Fly
por: Fan, Yihe, et al.
Publicado: (2026)
por: Fan, Yihe, et al.
Publicado: (2026)
Omission Constraints Decay While Commission Constraints Persist in Long-Context LLM Agents
por: Gamage, Yeran
Publicado: (2026)
por: Gamage, Yeran
Publicado: (2026)
Agent-Sentry: Bounding LLM Agents via Execution Provenance
por: Sequeira, Rohan, et al.
Publicado: (2026)
por: Sequeira, Rohan, et al.
Publicado: (2026)
WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
por: Chen, Yulin, et al.
Publicado: (2026)
por: Chen, Yulin, et al.
Publicado: (2026)
DRIP: Defending Prompt Injection via Token-wise Representation Editing and Residual Instruction Fusion
por: Liu, Ruofan, et al.
Publicado: (2025)
por: Liu, Ruofan, et al.
Publicado: (2025)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
por: Zhu, Kaijie, et al.
Publicado: (2025)
por: Zhu, Kaijie, et al.
Publicado: (2025)
Progent: Securing AI Agents with Privilege Control
por: Shi, Tianneng, et al.
Publicado: (2025)
por: Shi, Tianneng, et al.
Publicado: (2025)
Silent Egress: When Implicit Prompt Injection Makes LLM Agents Leak Without a Trace
por: Lan, Qianlong, et al.
Publicado: (2026)
por: Lan, Qianlong, et al.
Publicado: (2026)
Securing AI Agents Against Prompt Injection Attacks
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
Agent Safety Alignment via Reinforcement Learning
por: Sha, Zeyang, et al.
Publicado: (2025)
por: Sha, Zeyang, et al.
Publicado: (2025)
GhostEI-Bench: Do Mobile Agents Resilience to Environmental Injection in Dynamic On-Device Environments?
por: Chen, Chiyu, et al.
Publicado: (2025)
por: Chen, Chiyu, et al.
Publicado: (2025)
Unveiling Privacy Risks in LLM Agent Memory
por: Wang, Bo, et al.
Publicado: (2025)
por: Wang, Bo, et al.
Publicado: (2025)
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
por: Debi, Tanusree, et al.
Publicado: (2026)
por: Debi, Tanusree, et al.
Publicado: (2026)
A Vision for Access Control in LLM-based Agent Systems
por: Li, Xinfeng, et al.
Publicado: (2025)
por: Li, Xinfeng, et al.
Publicado: (2025)
Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems
por: Lee, Donghyun, et al.
Publicado: (2024)
por: Lee, Donghyun, et al.
Publicado: (2024)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
por: Zhao, Wei, et al.
Publicado: (2026)
por: Zhao, Wei, et al.
Publicado: (2026)
FlipAttack: Jailbreak LLMs via Flipping
por: Liu, Yue, et al.
Publicado: (2024)
por: Liu, Yue, et al.
Publicado: (2024)
OpenSage: Self-programming Agent Generation Engine
por: Li, Hongwei, et al.
Publicado: (2026)
por: Li, Hongwei, et al.
Publicado: (2026)
GuardReasoner-VL: Safeguarding VLMs via Reinforced Reasoning
por: Liu, Yue, et al.
Publicado: (2025)
por: Liu, Yue, et al.
Publicado: (2025)
Ejemplares similares
-
Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges
por: Yang, Xianglin, et al.
Publicado: (2026) -
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections
por: Cao, Tri, et al.
Publicado: (2026) -
VPI-Bench: Visual Prompt Injection Attacks for Computer-Use Agents
por: Cao, Tri, et al.
Publicado: (2025) -
Proteus: A Self-Evolving Red Team for Agent Skill Ecosystems
por: Zhou, Zhaojiacheng
Publicado: (2026) -
OEP: Poisoning Self-Evolving LLM Agents via Locally Correct but Non-Transferable Experiences
por: Wang, Kaixiang, et al.
Publicado: (2026)