Deep-Research Agents Can Be Poisoned via User-Generated Content
Fuente:
arXiv
Saved in:
| Main Authors: | Zhang, Tingwei, Triedman, Harold, Shmatikov, Vitaly |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Multi-Agent Systems Execute Arbitrary Malicious Code
by: Triedman, Harold, et al.
Published: (2025)
by: Triedman, Harold, et al.
Published: (2025)
Agent Meltdowns: The Road to Hell Is Paved with Helpful Agents
by: Jha, Rishi, et al.
Published: (2026)
by: Jha, Rishi, et al.
Published: (2026)
Breaking and Fixing Defenses Against Control-Flow Hijacking in Multi-Agent Systems
by: Jha, Rishi, et al.
Published: (2025)
by: Jha, Rishi, et al.
Published: (2025)
Adversarial Decoding: Generating Readable Documents for Adversarial Objectives
by: Zhang, Collin, et al.
Published: (2024)
by: Zhang, Collin, et al.
Published: (2024)
How to Steal Reasoning Without Reasoning Traces
by: Zhang, Tingwei, et al.
Published: (2026)
by: Zhang, Tingwei, et al.
Published: (2026)
Adversarial Illusions in Multi-Modal Embeddings
by: Zhang, Tingwei, et al.
Published: (2023)
by: Zhang, Tingwei, et al.
Published: (2023)
Differential Degradation Vulnerabilities in Censorship Circumvention Systems
by: Sun, Zhen, et al.
Published: (2024)
by: Sun, Zhen, et al.
Published: (2024)
Adversarial Hubness in Multi-Modal Retrieval
by: Zhang, Tingwei, et al.
Published: (2024)
by: Zhang, Tingwei, et al.
Published: (2024)
Self-interpreting Adversarial Images
by: Zhang, Tingwei, et al.
Published: (2024)
by: Zhang, Tingwei, et al.
Published: (2024)
Machine Against the RAG: Jamming Retrieval-Augmented Generation with Blocker Documents
by: Shafran, Avital, et al.
Published: (2024)
by: Shafran, Avital, et al.
Published: (2024)
Universal Zero-shot Embedding Inversion
by: Zhang, Collin, et al.
Published: (2025)
by: Zhang, Collin, et al.
Published: (2025)
Rerouting LLM Routers
by: Shafran, Avital, et al.
Published: (2025)
by: Shafran, Avital, et al.
Published: (2025)
MillStone: How Open-Minded Are LLMs?
by: Triedman, Harold, et al.
Published: (2025)
by: Triedman, Harold, et al.
Published: (2025)
Defending against Data Poisoning Attacks in Federated Learning via User Elimination
by: Galanis, Nick
Published: (2024)
by: Galanis, Nick
Published: (2024)
TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation
by: Ye, Hengkai, et al.
Published: (2026)
by: Ye, Hengkai, et al.
Published: (2026)
PoisonCatcher: Revealing and Identifying LDP Poisoning Attacks in IIoT
by: Shuai, Lisha, et al.
Published: (2024)
by: Shuai, Lisha, et al.
Published: (2024)
Pandora: Jailbreak GPTs by Retrieval Augmented Generation Poisoning
by: Deng, Gelei, et al.
Published: (2024)
by: Deng, Gelei, et al.
Published: (2024)
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
by: Chen, Zhaorun, et al.
Published: (2024)
by: Chen, Zhaorun, et al.
Published: (2024)
Electric Democracy: Proof of Work to secure Elections
by: Zuevsky, Vitaly
Published: (2022)
by: Zuevsky, Vitaly
Published: (2022)
MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content
by: Guo, Ruoqi, et al.
Published: (2026)
by: Guo, Ruoqi, et al.
Published: (2026)
Generate "Normal", Edit Poisoned: Branding Injection via Hint Embedding in Image Editing
by: Sun, Desen, et al.
Published: (2026)
by: Sun, Desen, et al.
Published: (2026)
MindGuard: Intrinsic Decision Inspection for Securing LLM Agents Against Metadata Poisoning
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
PoisonedParrot: Subtle Data Poisoning Attacks to Elicit Copyright-Infringing Content from Large Language Models
by: Panaitescu-Liess, Michael-Andrei, et al.
Published: (2025)
by: Panaitescu-Liess, Michael-Andrei, et al.
Published: (2025)
MIRAGE: Misleading Retrieval-Augmented Generation via Black-box and Query-agnostic Poisoning Attacks
by: Chen, Tailun, et al.
Published: (2025)
by: Chen, Tailun, et al.
Published: (2025)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)
by: Zou, Wei, et al.
Published: (2026)
LoopTrap: Termination Poisoning Attacks on LLM Agents
by: Xu, Huiyu, et al.
Published: (2026)
by: Xu, Huiyu, et al.
Published: (2026)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
by: Tie, Guiyao, et al.
Published: (2026)
by: Tie, Guiyao, et al.
Published: (2026)
CPA-RAG:Covert Poisoning Attacks on Retrieval-Augmented Generation in Large Language Models
by: Li, Chunyang, et al.
Published: (2025)
by: Li, Chunyang, et al.
Published: (2025)
Blockchain Address Poisoning
by: Tsuchiya, Taro, et al.
Published: (2025)
by: Tsuchiya, Taro, et al.
Published: (2025)
Poisoned-MRAG: Knowledge Poisoning Attacks to Multimodal Retrieval Augmented Generation
by: Liu, Yinuo, et al.
Published: (2025)
by: Liu, Yinuo, et al.
Published: (2025)
Data Poisoning in Deep Learning: A Survey
by: Zhao, Pinlong, et al.
Published: (2025)
by: Zhao, Pinlong, et al.
Published: (2025)
Model Poisoning Attacks to Federated Learning via Multi-Round Consistency
by: Xie, Yueqi, et al.
Published: (2024)
by: Xie, Yueqi, et al.
Published: (2024)
Can In-Context Reinforcement Learning Recover From Reward Poisoning Attacks?
by: Sasnauskas, Paulius, et al.
Published: (2025)
by: Sasnauskas, Paulius, et al.
Published: (2025)
Poisoning the Pixels: Revisiting Backdoor Attacks on Semantic Segmentation
by: Zhang, Guangsheng, et al.
Published: (2026)
by: Zhang, Guangsheng, et al.
Published: (2026)
Data Poisoning for In-context Learning
by: He, Pengfei, et al.
Published: (2024)
by: He, Pengfei, et al.
Published: (2024)
Poisoning Federated Recommender Systems with Fake Users
by: Yin, Ming, et al.
Published: (2024)
by: Yin, Ming, et al.
Published: (2024)
Poisoning Prevention in Federated Learning and Differential Privacy via Stateful Proofs of Execution
by: Rattanavipanon, Norrathep, et al.
Published: (2024)
by: Rattanavipanon, Norrathep, et al.
Published: (2024)
Defending Against Neural Network Model Inversion Attacks via Data Poisoning
by: Zhou, Shuai, et al.
Published: (2024)
by: Zhou, Shuai, et al.
Published: (2024)
Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking
by: Wu, Yu-Hang, et al.
Published: (2025)
by: Wu, Yu-Hang, et al.
Published: (2025)
Visualizing the Shadows: Unveiling Data Poisoning Behaviors in Federated Learning
by: Zhang, Xueqing, et al.
Published: (2024)
by: Zhang, Xueqing, et al.
Published: (2024)
Similar Items
-
Multi-Agent Systems Execute Arbitrary Malicious Code
by: Triedman, Harold, et al.
Published: (2025) -
Agent Meltdowns: The Road to Hell Is Paved with Helpful Agents
by: Jha, Rishi, et al.
Published: (2026) -
Breaking and Fixing Defenses Against Control-Flow Hijacking in Multi-Agent Systems
by: Jha, Rishi, et al.
Published: (2025) -
Adversarial Decoding: Generating Readable Documents for Adversarial Objectives
by: Zhang, Collin, et al.
Published: (2024) -
How to Steal Reasoning Without Reasoning Traces
by: Zhang, Tingwei, et al.
Published: (2026)