ICON: Indirect Prompt Injection Defense for Agents based on Inference-Time Correction
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Wang, Che, Zhang, Fuyao, Zhang, Jiaming, Zhang, Ziqi, Wang, Yinghui, Huang, Longtao, Gao, Jianbo, Chen, Zhong, Lim, Wei Yang Bryan |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
von: Wang, Che, et al.
Veröffentlicht: (2026)
von: Wang, Che, et al.
Veröffentlicht: (2026)
DualTAP: A Dual-Task Adversarial Protector for Mobile MLLM Agents
von: Zhang, Fuyao, et al.
Veröffentlicht: (2025)
von: Zhang, Fuyao, et al.
Veröffentlicht: (2025)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
von: Zhu, Kaijie, et al.
Veröffentlicht: (2025)
von: Zhu, Kaijie, et al.
Veröffentlicht: (2025)
VENOMREC: Cross-Modal Interactive Poisoning for Targeted Promotion in Multimodal LLM Recommender Systems
von: Guan, Guowei, et al.
Veröffentlicht: (2026)
von: Guan, Guowei, et al.
Veröffentlicht: (2026)
FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks
von: Wang, Jiongxiao, et al.
Veröffentlicht: (2024)
von: Wang, Jiongxiao, et al.
Veröffentlicht: (2024)
QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
von: Xie, Yuchong, et al.
Veröffentlicht: (2025)
Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
Can Indirect Prompt Injection Attacks Be Detected and Removed?
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
TopicAttack: An Indirect Prompt Injection Attack via Topic Transition
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
von: Wu, Fangzhou, et al.
Veröffentlicht: (2024)
von: Wu, Fangzhou, et al.
Veröffentlicht: (2024)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
von: Wang, Yihan, et al.
Veröffentlicht: (2025)
von: Wang, Yihan, et al.
Veröffentlicht: (2025)
Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives
von: Khodayari, Soheil, et al.
Veröffentlicht: (2026)
von: Khodayari, Soheil, et al.
Veröffentlicht: (2026)
Backdoor-Powered Prompt Injection Attacks Nullify Defense Methods
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
von: Chen, Yulin, et al.
Veröffentlicht: (2025)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
von: Xiang, Chong, et al.
Veröffentlicht: (2026)
von: Xiang, Chong, et al.
Veröffentlicht: (2026)
IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents
von: An, Hengyu, et al.
Veröffentlicht: (2025)
von: An, Hengyu, et al.
Veröffentlicht: (2025)
Defense Against Prompt Injection Attack by Leveraging Attack Techniques
von: Chen, Yulin, et al.
Veröffentlicht: (2024)
von: Chen, Yulin, et al.
Veröffentlicht: (2024)
Hidden-in-Plain-Text: A Benchmark for Social-Web Indirect Prompt Injection in RAG
von: Guo, Haoze, et al.
Veröffentlicht: (2026)
von: Guo, Haoze, et al.
Veröffentlicht: (2026)
PlanGuard: Defending Agents against Indirect Prompt Injection via Planning-based Consistency Verification
von: Gong, Guangyu, et al.
Veröffentlicht: (2026)
von: Gong, Guangyu, et al.
Veröffentlicht: (2026)
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections
von: Cao, Tri, et al.
Veröffentlicht: (2026)
von: Cao, Tri, et al.
Veröffentlicht: (2026)
PINA: Prompt Injection Attack against Navigation Agents
von: Liu, Jiani, et al.
Veröffentlicht: (2026)
von: Liu, Jiani, et al.
Veröffentlicht: (2026)
Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
von: Zhong, Yinan, et al.
Veröffentlicht: (2025)
von: Zhong, Yinan, et al.
Veröffentlicht: (2025)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
von: Wang, Zhun, et al.
Veröffentlicht: (2025)
von: Wang, Zhun, et al.
Veröffentlicht: (2025)
Defending Against Prompt Injection With a Few DefensiveTokens
von: Chen, Sizhe, et al.
Veröffentlicht: (2025)
von: Chen, Sizhe, et al.
Veröffentlicht: (2025)
VortexPIA: Indirect Prompt Injection Attack against LLMs for Efficient Extraction of User Privacy
von: Cui, Yu, et al.
Veröffentlicht: (2025)
von: Cui, Yu, et al.
Veröffentlicht: (2025)
The Cognitive Firewall:Securing Browser Based AI Agents Against Indirect Prompt Injection Via Hybrid Edge Cloud Defense
von: Lan, Qianlong, et al.
Veröffentlicht: (2026)
von: Lan, Qianlong, et al.
Veröffentlicht: (2026)
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents
von: Shah, Harsh
Veröffentlicht: (2026)
von: Shah, Harsh
Veröffentlicht: (2026)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
von: Zhao, Wei, et al.
Veröffentlicht: (2026)
von: Zhao, Wei, et al.
Veröffentlicht: (2026)
Defending against Indirect Prompt Injection by Instruction Detection
von: Wen, Tongyu, et al.
Veröffentlicht: (2025)
von: Wen, Tongyu, et al.
Veröffentlicht: (2025)
ARGUS: Defending Against Multimodal Indirect Prompt Injection via Steering Instruction-Following Behavior
von: Lu, Weikai, et al.
Veröffentlicht: (2025)
von: Lu, Weikai, et al.
Veröffentlicht: (2025)
PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses
von: Yin, Chenlong, et al.
Veröffentlicht: (2026)
von: Yin, Chenlong, et al.
Veröffentlicht: (2026)
AgentWatcher: A Rule-based Prompt Injection Monitor
von: Wang, Yanting, et al.
Veröffentlicht: (2026)
von: Wang, Yanting, et al.
Veröffentlicht: (2026)
PromptArmor: Simple yet Effective Prompt Injection Defenses
von: Shi, Tianneng, et al.
Veröffentlicht: (2025)
von: Shi, Tianneng, et al.
Veröffentlicht: (2025)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
von: He, Yu, et al.
Veröffentlicht: (2026)
von: He, Yu, et al.
Veröffentlicht: (2026)
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection
von: Zhao, Lei, et al.
Veröffentlicht: (2026)
von: Zhao, Lei, et al.
Veröffentlicht: (2026)
Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?
von: Bhagwatkar, Rishika, et al.
Veröffentlicht: (2025)
von: Bhagwatkar, Rishika, et al.
Veröffentlicht: (2025)
PromptSleuth: Detecting Prompt Injection via Semantic Intent Invariance
von: Wang, Mengxiao, et al.
Veröffentlicht: (2025)
von: Wang, Mengxiao, et al.
Veröffentlicht: (2025)
Verifiably Forgotten? Gradient Differences Still Enable Data Reconstruction in Federated Unlearning
von: Zhang, Fuyao, et al.
Veröffentlicht: (2025)
von: Zhang, Fuyao, et al.
Veröffentlicht: (2025)
InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
von: Zhan, Qiusi, et al.
Veröffentlicht: (2024)
von: Zhan, Qiusi, et al.
Veröffentlicht: (2024)
Dynamic Probabilistic Noise Injection for Membership Inference Defense
von: Forough, Javad, et al.
Veröffentlicht: (2025)
von: Forough, Javad, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
von: Wang, Che, et al.
Veröffentlicht: (2026) -
DualTAP: A Dual-Task Adversarial Protector for Mobile MLLM Agents
von: Zhang, Fuyao, et al.
Veröffentlicht: (2025) -
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
von: Zhu, Kaijie, et al.
Veröffentlicht: (2025) -
VENOMREC: Cross-Modal Interactive Poisoning for Targeted Promotion in Multimodal LLM Recommender Systems
von: Guan, Guowei, et al.
Veröffentlicht: (2026) -
FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks
von: Wang, Jiongxiao, et al.
Veröffentlicht: (2024)