AI Agents May Always Fall for Prompt Injections
Fuente:
arXiv
Saved in:
| Main Authors: | Abdelnabi, Sahar, Bagdasarian, Eugene |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
ConVerse: Benchmarking Contextual Safety in Agent-to-Agent Conversations
by: Gomaa, Amr, et al.
Published: (2025)
by: Gomaa, Amr, et al.
Published: (2025)
Firewalls to Secure Dynamic LLM Agentic Networks
by: Abdelnabi, Sahar, et al.
Published: (2025)
by: Abdelnabi, Sahar, et al.
Published: (2025)
Get my drift? Catching LLM Task Drift with Activation Deltas
by: Abdelnabi, Sahar, et al.
Published: (2024)
by: Abdelnabi, Sahar, et al.
Published: (2024)
Contextual Agent Security: A Policy for Every Purpose
by: Tsai, Lillian, et al.
Published: (2025)
by: Tsai, Lillian, et al.
Published: (2025)
Terrarium: Revisiting the Blackboard for Multi-Agent Safety, Privacy, and Security Studies
by: Nakamura, Mason, et al.
Published: (2025)
by: Nakamura, Mason, et al.
Published: (2025)
The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysis
by: Wang, Peiran, et al.
Published: (2026)
by: Wang, Peiran, et al.
Published: (2026)
SecureForge: Finding and Preventing Vulnerabilities in LLM-Generated Code via Prompt Optimization
by: Liu, Houjun, et al.
Published: (2026)
by: Liu, Houjun, et al.
Published: (2026)
InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
by: Zhan, Qiusi, et al.
Published: (2024)
by: Zhan, Qiusi, et al.
Published: (2024)
Prompt Injection Vulnerability of Consensus Generating Applications in Digital Democracy
by: Gudiño-Rosero, Jairo, et al.
Published: (2025)
by: Gudiño-Rosero, Jairo, et al.
Published: (2025)
AirGapAgent: Protecting Privacy-Conscious Conversational Agents
by: Bagdasarian, Eugene, et al.
Published: (2024)
by: Bagdasarian, Eugene, et al.
Published: (2024)
Fingerprinting LLMs via Prompt Injection
by: Hu, Yuepeng, et al.
Published: (2025)
by: Hu, Yuepeng, et al.
Published: (2025)
When Your Reviewer is an LLM: Biases, Divergence, and Prompt Injection Risks in Peer Review
by: Zhu, Changjia, et al.
Published: (2025)
by: Zhu, Changjia, et al.
Published: (2025)
Is Your Prompt Safe? Investigating Prompt Injection Attacks Against Open-Source LLMs
by: Wang, Jiawen, et al.
Published: (2025)
by: Wang, Jiawen, et al.
Published: (2025)
"Give a Positive Review Only": An Early Investigation Into In-Paper Prompt Injection Attacks and Defenses for AI Reviewers
by: Zhou, Qin, et al.
Published: (2025)
by: Zhou, Qin, et al.
Published: (2025)
WAInjectBench: Benchmarking Prompt Injection Detections for Web Agents
by: Liu, Yinuo, et al.
Published: (2025)
by: Liu, Yinuo, et al.
Published: (2025)
AttnTrace: Contextual Attribution of Prompt Injection and Knowledge Corruption
by: Wang, Yanting, et al.
Published: (2025)
by: Wang, Yanting, et al.
Published: (2025)
WebSentinel: Detecting and Localizing Prompt Injection Attacks for Web Agents
by: Wang, Xilong, et al.
Published: (2026)
by: Wang, Xilong, et al.
Published: (2026)
Designing AI-Enabled Countermeasures to Cognitive Warfare
by: van Diggelen, Jurriaan, et al.
Published: (2025)
by: van Diggelen, Jurriaan, et al.
Published: (2025)
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection
by: Munirathinam, Thamilvendhan
Published: (2026)
by: Munirathinam, Thamilvendhan
Published: (2026)
Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
by: Maloyan, Narek, et al.
Published: (2025)
by: Maloyan, Narek, et al.
Published: (2025)
Automatic Pseudo-Harmful Prompt Generation for Evaluating False Refusals in Large Language Models
by: An, Bang, et al.
Published: (2024)
by: An, Bang, et al.
Published: (2024)
Prompt Injection as Role Confusion
by: Ye, Charles, et al.
Published: (2026)
by: Ye, Charles, et al.
Published: (2026)
FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks
by: Wang, Jiongxiao, et al.
Published: (2024)
by: Wang, Jiongxiao, et al.
Published: (2024)
May I have your Attention? Breaking Fine-Tuning based Prompt Injection Defenses using Architecture-Aware Attacks
by: Pandya, Nishit V., et al.
Published: (2025)
by: Pandya, Nishit V., et al.
Published: (2025)
Zero-Shot Embedding Drift Detection: A Lightweight Defense Against Prompt Injections in LLMs
by: Sekar, Anirudh, et al.
Published: (2026)
by: Sekar, Anirudh, et al.
Published: (2026)
Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Signals
by: Akinrele, Akindoyin, et al.
Published: (2026)
by: Akinrele, Akindoyin, et al.
Published: (2026)
Red Teaming the Mind of the Machine: A Systematic Evaluation of Prompt Injection and Jailbreak Vulnerabilities in LLMs
by: Pathade, Chetan
Published: (2025)
by: Pathade, Chetan
Published: (2025)
Applying Pre-trained Multilingual BERT in Embeddings for Improved Malicious Prompt Injection Attacks Detection
by: Rahman, Md Abdur, et al.
Published: (2024)
by: Rahman, Md Abdur, et al.
Published: (2024)
Let's Measure the Elephant in the Room: Facilitating Personalized Automated Analysis of Privacy Policies at Scale
by: Zhao, Rui, et al.
Published: (2025)
by: Zhao, Rui, et al.
Published: (2025)
An Investigation into Misuse of Java Security APIs by Large Language Models
by: Mousavi, Zahra, et al.
Published: (2024)
by: Mousavi, Zahra, et al.
Published: (2024)
Domain-Independent Deception: A New Taxonomy and Linguistic Analysis
by: Verma, Rakesh M., et al.
Published: (2024)
by: Verma, Rakesh M., et al.
Published: (2024)
Data Defenses Against Large Language Models
by: Agnew, William, et al.
Published: (2024)
by: Agnew, William, et al.
Published: (2024)
How Susceptible are Large Language Models to Ideological Manipulation?
by: Chen, Kai, et al.
Published: (2024)
by: Chen, Kai, et al.
Published: (2024)
Steering the CensorShip: Uncovering Representation Vectors for LLM "Thought" Control
by: Cyberey, Hannah, et al.
Published: (2025)
by: Cyberey, Hannah, et al.
Published: (2025)
Nuclear Deployed: Analyzing Catastrophic Risks in Decision-making of Autonomous LLM Agents
by: Xu, Rongwu, et al.
Published: (2025)
by: Xu, Rongwu, et al.
Published: (2025)
Can LLMs Infer Conversational Agent Users' Personality Traits from Chat History?
by: Cögendez, Derya, et al.
Published: (2026)
by: Cögendez, Derya, et al.
Published: (2026)
Complete Evasion, Zero Modification: PDF Attacks on AI Text Detection
by: Creo, Aldan
Published: (2025)
by: Creo, Aldan
Published: (2025)
Blueprints of Trust: AI System Cards for End to End Transparency and Governance
by: Sidhpurwala, Huzaifa, et al.
Published: (2025)
by: Sidhpurwala, Huzaifa, et al.
Published: (2025)
How Well Can LLM Agents Simulate End-User Security and Privacy Attitudes and Behaviors?
by: Li, Yuxuan, et al.
Published: (2026)
by: Li, Yuxuan, et al.
Published: (2026)
MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content
by: Guo, Ruoqi, et al.
Published: (2026)
by: Guo, Ruoqi, et al.
Published: (2026)
Similar Items
-
ConVerse: Benchmarking Contextual Safety in Agent-to-Agent Conversations
by: Gomaa, Amr, et al.
Published: (2025) -
Firewalls to Secure Dynamic LLM Agentic Networks
by: Abdelnabi, Sahar, et al.
Published: (2025) -
Get my drift? Catching LLM Task Drift with Activation Deltas
by: Abdelnabi, Sahar, et al.
Published: (2024) -
Contextual Agent Security: A Policy for Every Purpose
by: Tsai, Lillian, et al.
Published: (2025) -
Terrarium: Revisiting the Blackboard for Multi-Agent Safety, Privacy, and Security Studies
by: Nakamura, Mason, et al.
Published: (2025)