cs.AISep 29, 2026

Divide and Inject: Can Agents Reconstruct an Indirect Prompt Injection from Fragments?

Authors: Michael Lee, Zhipeng Wei, Yue Dong, N. Benjamin Erichson

Organizations: International Computer Science Institute · DSO National Laboratories · UC Riverside · Lawrence Berkeley National Lab

Abstract

Agentic systems are now being widely used to orchestrate tools and reason over long contexts. However, the improving capabilities of the large language models powering these agents also create new attack surfaces for indirect prompt injection. In particular, an attacker may not need to place a complete malicious instruction in retrieved content if the agent can reconstruct the objective from incomplete fragments distributed across a long context. In this work, we introduce adaptive long-context prompt injection (AdaLCPI), which combines long-context fragmentation with adaptive search. AdaLCPI splits an attack objective into incomplete fragments, embeds them in external content retrieved through the agent's tools, and uses a reconstruction cue to prompt the agent to combine them. It then iteratively refines the fragments and cue with OpenEvolve using graded scoring and natural-language execution feedback from the target agent. Empirically, AdaLCPI achieves higher attack success than strong adaptive baselines, reaching 61.4% macro-average ASR compared with 32.8% for Trojan Hippo-style and 30.0% for AgentVigil. Safety evaluations should therefore test whether agents remain robust when harmful objectives must be reconstructed from incomplete fragments.

Figures & tables

Appendix figures & tables20 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization

    May 23, 2026Zixuan Chen, Jiaxiang Chen, Li Luo +4Indirect Prompt InjectionLarge Language Model Agents

  2. Assessing Automated Prompt Injection Attacks in Agentic Environments

    Jun 9, 2026David Hofer, Edoardo Debenedetti, Florian TramèrIndirect Prompt InjectionLarge Language Model Agents

  3. AI Agents May Always Fall for Prompt Injections

    May 17, 2026Sahar Abdelnabi, Eugene BagdasarianArtificial Intelligence SafetyArtificial Intelligence Agents