Prompt Injection Attacks on AI Agents

Latest papers 108

All topics
CardsList
  1. Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy

    Oct 7, 2026Georgios Koutidis, Nikolaos Kekatos, Tom Nianios +1LLMs for CybersecurityTool Access Control for LLM Agents

  2. Secure-CUA: Controlling Untrusted Influence in Computer-Use Agents

    Oct 7, 2026Sarthak Choudhary, Mihai Christodorescu, Ashish Hooda +3Computer-Use AgentsAI Agent Security

  3. AdvSim2Real : Training Web Agents Against Adaptive Prompt Injection in a Web World Model

    Oct 6, 2026Sarim Hashmi, Mukul Ranjan, Kshitij Mishra +3Adversarial TrainingSim-to-Real Transfer

  4. Surviving the Router: Optimizing Skill Injections for Retrieval and Execution

    Oct 6, 2026Haneen Najjar, Luca Scionis, Haritz Puerto +1AI Agent Security BenchmarksLLM Agent Skill Retrieval

  5. Towards a Unified Misuse Monitoring Benchmark

    Oct 5, 2026Aniruddh Pramod, James Oldfield, Adel BibiAI Agent SecurityAI Agent Monitoring

  6. Can CaMeLs Talk? Securing Multi-Agent Systems Against Indirect Prompt Injection Attacks

    Oct 5, 2026James Peters-Gill, Avi Semler, Henning Bartsch +2AI Agent Security BenchmarksInformation Flow Control

  7. Readable Before Actionable: Causal Tracing of Indirect Prompt Injection

    Oct 4, 2026Zhe Yu, Wenpeng Xing, Xingxing Yang +1Causal Reasoning in Language ModelsIndirect Prompt Injection

  8. Blocking at the Boundary: Auditing Long-Horizon Agents against Staged Prompt Injection

    Oct 4, 2026Jingkai Liu, Yufei Han, Xiaoting Lyu +2Prompt InjectionAI Agent Auditing

  9. APEX: Active Protection at Execution Boundaries for LLM Agents

    Oct 3, 2026Xinran Zheng, Xin Fan Guo, Zhiqiang Hao +7AI Agent SecurityPrompt Injection Defense

  10. Chaining Skills to Hijack LLM Agents

    Oct 1, 2026Tian Dong, Zixuan Ma, Haodong Zhao +3LLM Agent SecurityAI Agent Safety

  11. ActionGuard: Tool Call Authorization under Poisoned Skills

    Sep 30, 2026Jihun Han, Yejin Jang, Byung Il Kwak +1Runtime Enforcement for AI AgentsPrompt Injection Defense

  12. Can Agents Trust Their Skills? Uncovering Unsafe Chains of Trust in Skill-Based LLM Agents

    Sep 30, 2026Yan Wang, Zhihao Zhang, Ke Chen +5LLM Agent SecurityPrompt Injection Attacks on AI Agents

  13. The Backdrop Exposes What the World Around an Agent Costs It

    Sep 29, 2026Nusrat Jahan Lia, Shubhashis Roy DiptaAI Agent ReliabilityPrompt Injection Attacks on AI Agents

  14. Divide and Inject: Can Agents Reconstruct an Indirect Prompt Injection from Fragments?

    Sep 29, 2026Michael Lee, Zhipeng Wei, Yue Dong +1Indirect Prompt InjectionPrompt Injection Attacks

  15. Render Before Reading: Visual Rendering as a Prompt Injection Defense

    Sep 28, 2026Jie Zhang, Andrei Baroian, Jan N. van Rijn +2Multimodal Large Language ModelsModality Gap in VLMs

  16. Share-Borne AI Virus: Memory-Hopping Attacks Across LLM Agents

    Sep 28, 2026Sidharth Pulipaka, Ansh Sharma, Stanislau Hlebik +4AI Agent SecurityAgent Memory Poisoning

  17. Same Bytes, Different Authority: Reserved-Token Representations in Chat-Template Prompt Injection

    Sep 28, 2026Yan Zhan, Yunze Song, Mengkai Hou +3Prompt InjectionPrompt Injection Defense

  18. MMSkillRisk: Can Agents Stay Safe When Multimodal Skills Become Traps?

    Sep 28, 2026Lingqi Jiang, Jialuo Chen, Jianan Ma +8Prompt Injection Attacks on AI AgentsAgent Skill Security Auditing

  19. Certified Multi-Source Integrity for Structured Agent Actions

    Sep 28, 2026Anmol Pandey, Aditya Jain, Liang Chen +2Data ProvenanceLLM Agent Security

  20. When Consent Outlives Context: Residual Authority Replay in Long-Lived Agents

    Sep 27, 2026Zhihao Zhang, Chao Wang, Rujia Li +3LLM Agent SecurityPrompt Injection Attacks on AI Agents

  21. Climbing the Hill: Prompt Injection Red-Teaming Against Frontier Models with Curriculum Reinforcement Learning

    Sep 27, 2026Chenlong Yin, Xiaolong Jin, Wei Zou +2Adversarial Attacks on LLMsLLM Red Teaming

  22. ActGov: Governing LLM Agent Actions via Policy-Constrained Validation

    Sep 21, 2026Kaiyuan Zhang, Yuke Peng, Ke Jiang +1LLM Agent SecurityRuntime Enforcement for AI Agents

  23. Red-Teaming Auto Mode: Improving Blocking Classifiers Against Malign Coding Agents

    Sep 17, 2026Alex Remedios, Simon Storf, Fabien Roger +1AI Agent SecurityAI Agent Monitoring

  24. Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection

    Sep 14, 2026Keertana Chidambaram, Andrew Ilyas, Vasilis SyrgkanisLLM SecurityPrompt Injection Attacks on AI Agents

  25. Universal Defenses for Tool-Integrated LLM Agents Against Adversarial Attacks

    Sep 14, 2026Xiaoyan Li, Yunli WangAdversarial Attacks on LLMsBackdoor Defense in LLMs

  26. ActGuard: Pre-execution Action Auditing against Indirect Prompt Injection in LLM Agents

    Sep 14, 2026Bingzheng Wang, Xiaoyan Gu, Wentao Wang +3Runtime Enforcement for AI AgentsPrompt Injection Defense