Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents
Fuente:
arXiv
Guardado en:
| Autores principales: | Maloyan, Narek, Namiot, Dmitry |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
por: Maloyan, Narek, et al.
Publicado: (2026)
por: Maloyan, Narek, et al.
Publicado: (2026)
Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
por: Maloyan, Narek, et al.
Publicado: (2026)
por: Maloyan, Narek, et al.
Publicado: (2026)
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
por: Maloyan, Narek, et al.
Publicado: (2025)
por: Maloyan, Narek, et al.
Publicado: (2025)
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
por: Maloyan, Narek, et al.
Publicado: (2025)
por: Maloyan, Narek, et al.
Publicado: (2025)
AI Agents May Always Fall for Prompt Injections
por: Abdelnabi, Sahar, et al.
Publicado: (2026)
por: Abdelnabi, Sahar, et al.
Publicado: (2026)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
por: Wang, Yihan, et al.
Publicado: (2025)
por: Wang, Yihan, et al.
Publicado: (2025)
Cross-Scale Persistence Analysis of EM Side-Channels for Reference-Free Detection of Always-On Hardware Trojans
por: Tahghigh, Mahsa, et al.
Publicado: (2026)
por: Tahghigh, Mahsa, et al.
Publicado: (2026)
Securing AI Agents Against Prompt Injection Attacks
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training
por: Hubinger, Evan, et al.
Publicado: (2024)
por: Hubinger, Evan, et al.
Publicado: (2024)
Cybersecurity AI: Hacking the AI Hackers via Prompt Injection
por: Mayoral-Vilches, Víctor, et al.
Publicado: (2025)
por: Mayoral-Vilches, Víctor, et al.
Publicado: (2025)
PINA: Prompt Injection Attack against Navigation Agents
por: Liu, Jiani, et al.
Publicado: (2026)
por: Liu, Jiani, et al.
Publicado: (2026)
Prompt Injection Attack to Tool Selection in LLM Agents
por: Shi, Jiawen, et al.
Publicado: (2025)
por: Shi, Jiawen, et al.
Publicado: (2025)
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
por: Wang, Reachal, et al.
Publicado: (2025)
por: Wang, Reachal, et al.
Publicado: (2025)
AgentWatcher: A Rule-based Prompt Injection Monitor
por: Wang, Yanting, et al.
Publicado: (2026)
por: Wang, Yanting, et al.
Publicado: (2026)
SleeperNets: Universal Backdoor Poisoning Attacks Against Reinforcement Learning Agents
por: Rathbun, Ethan, et al.
Publicado: (2024)
por: Rathbun, Ethan, et al.
Publicado: (2024)
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
por: Ying, Zonghao, et al.
Publicado: (2026)
por: Ying, Zonghao, et al.
Publicado: (2026)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
por: Zhu, Kaijie, et al.
Publicado: (2025)
por: Zhu, Kaijie, et al.
Publicado: (2025)
From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
por: Ferrag, Mohamed Amine, et al.
Publicado: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
por: Wang, Zhilong, et al.
Publicado: (2025)
por: Wang, Zhilong, et al.
Publicado: (2025)
PromptShield: Deployable Detection for Prompt Injection Attacks
por: Jacob, Dennis, et al.
Publicado: (2025)
por: Jacob, Dennis, et al.
Publicado: (2025)
System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
por: Li, Zongze, et al.
Publicado: (2025)
por: Li, Zongze, et al.
Publicado: (2025)
WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
por: Chen, Yulin, et al.
Publicado: (2026)
por: Chen, Yulin, et al.
Publicado: (2026)
LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents
por: Shah, Harsh
Publicado: (2026)
por: Shah, Harsh
Publicado: (2026)
MAD-Spear: A Conformity-Driven Prompt Injection Attack on Multi-Agent Debate Systems
por: Cui, Yu, et al.
Publicado: (2025)
por: Cui, Yu, et al.
Publicado: (2025)
Are AI-assisted Development Tools Immune to Prompt Injection?
por: Huang, Charoes, et al.
Publicado: (2026)
por: Huang, Charoes, et al.
Publicado: (2026)
Prompt Injection 2.0: Hybrid AI Threats
por: McHugh, Jeremy, et al.
Publicado: (2025)
por: McHugh, Jeremy, et al.
Publicado: (2025)
Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
por: Yang, Xianglin, et al.
Publicado: (2026)
por: Yang, Xianglin, et al.
Publicado: (2026)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
por: Xiang, Chong, et al.
Publicado: (2026)
por: Xiang, Chong, et al.
Publicado: (2026)
PromptSleuth: Detecting Prompt Injection via Semantic Intent Invariance
por: Wang, Mengxiao, et al.
Publicado: (2025)
por: Wang, Mengxiao, et al.
Publicado: (2025)
Dual-Guard: Dual-Channel Latent Watermarking for Provenance and Tamper Localization in Diffusion Images
por: Xie, JinFeng, et al.
Publicado: (2026)
por: Xie, JinFeng, et al.
Publicado: (2026)
The Vulnerability of LLM Rankers to Prompt Injection Attacks
por: Yin, Yu, et al.
Publicado: (2026)
por: Yin, Yu, et al.
Publicado: (2026)
Design Patterns for Securing LLM Agents against Prompt Injections
por: Beurer-Kellner, Luca, et al.
Publicado: (2025)
por: Beurer-Kellner, Luca, et al.
Publicado: (2025)
Defending Against Prompt Injection with DataFilter
por: Wang, Yizhu, et al.
Publicado: (2025)
por: Wang, Yizhu, et al.
Publicado: (2025)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
por: He, Yu, et al.
Publicado: (2026)
por: He, Yu, et al.
Publicado: (2026)
PlanGuard: Defending Agents against Indirect Prompt Injection via Planning-based Consistency Verification
por: Gong, Guangyu, et al.
Publicado: (2026)
por: Gong, Guangyu, et al.
Publicado: (2026)
Agentic AI for Autonomous Defense in Software Supply Chain Security: Beyond Provenance to Vulnerability Mitigation
por: Syed, Toqeer Ali, et al.
Publicado: (2025)
por: Syed, Toqeer Ali, et al.
Publicado: (2025)
BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents
por: Zhang, Kaiyuan, et al.
Publicado: (2025)
por: Zhang, Kaiyuan, et al.
Publicado: (2025)
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
por: Chia-Pei, et al.
Publicado: (2026)
por: Chia-Pei, et al.
Publicado: (2026)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
por: Dziemian, Mateusz, et al.
Publicado: (2026)
por: Dziemian, Mateusz, et al.
Publicado: (2026)
The Agent Economy: A Blockchain-Based Foundation for Autonomous AI Agents
por: Xu, Minghui
Publicado: (2026)
por: Xu, Minghui
Publicado: (2026)
Ejemplares similares
-
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
por: Maloyan, Narek, et al.
Publicado: (2026) -
Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
por: Maloyan, Narek, et al.
Publicado: (2026) -
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
por: Maloyan, Narek, et al.
Publicado: (2025) -
Investigating the Vulnerability of LLM-as-a-Judge Architectures to Prompt-Injection Attacks
por: Maloyan, Narek, et al.
Publicado: (2025) -
AI Agents May Always Fall for Prompt Injections
por: Abdelnabi, Sahar, et al.
Publicado: (2026)