Prompt Injection Attacks on AI Agents

Latest papers 108

All topics
CardsList
  1. An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI Frameworks

    Sep 10, 2026Viet K. Nguyen, Mohammad I. HusainAI Agent SecurityAI Agent Security Benchmarks

  2. CoER: Defending against Adaptive Indirect Prompt Injection via Adversarial Co-Evolution and Refinement

    Sep 7, 2026Boyang Zhang, Qingxin Xiao, Lingwei Dang +1Reinforcement LearningAI Agent Security

  3. Rethinking Indirect Prompt Injection as a Test-Time Search Problem

    Sep 7, 2026Duong M. Nguyen, Joon Sik Kim, Blazej Manczak +1Inference-Time SearchAI Agent Security

  4. SIR: Self-improving Red-teaming for Compute Use Agents

    Aug 31, 2026Chen Xiong, Zhiyuan He, Pin-Yu Chen +2Computer-Use AgentsIndirect Prompt Injection

  5. Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection

    Aug 30, 2026Wujie Xiong, Rabimba Karanjai, Yang Lu +2LLM Agent SecurityInformation Flow Control

  6. ToolHazard: Scaling Adversarial Environments for Security Evaluation and Alignment of LLM-based Agents

    Aug 12, 2026Yutao Mou, Pengfei Yang, Zhe Yin +6AI Agent EvaluationAdversarial Scenario Generation

  7. On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models

    Aug 11, 2026Md Jafrin Hossain, Mohammad Arif Hossain, Nirwan AnsariLLM Agent SecurityLLM Security

  8. ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents

    Aug 10, 2026Hongwei Yao, Yiming Liu, Meihui Chen +6AI Agent SecurityAI Agent Safety

  9. Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection

    Aug 9, 2026Rahul Deivasigamani, Sayeda Faatin Alvi, Derqui Andrea +2AI Agent SecurityLLM Agent Security

  10. Toward Metacognitive One-Shot Indirect Prompt Injection: Strategy Abstraction Via Outcome-Conditioned Reflection

    Aug 9, 2026Sihan Hou, Xinmeng Hou, Zhijun Zhang +5AI Agent Security BenchmarksIndirect Prompt Injection

  11. Persistent Semantic Entities in Tool-Augmented LLM Systems

    Aug 8, 2026Zhaohui WangAgent MemoryTool-Augmented Language Model Agents

  12. Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture

    Aug 6, 2026Leo Sambrook, Sampo SovioMCP SecurityAI Agent Security

  13. Hijacking Robots with a Piece of Paper: A Systematic Study of Physical Prompt Injection in VLM-Controlled Robots

    Aug 6, 2026S. M . Bhagya P. Samarakoon, M. A. Viraj J. Muthugala, W. K. R. Sachinthana +1VLM RobustnessAdversarial Attacks on VLMs

  14. Breadcrumbing Search Agents

    Aug 5, 2026Xuebin Li, Hanqing Zhao, Siyuan Liang +4Adversarial AttacksWeb Search Agents

  15. Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents

    Aug 3, 2026Jia-Chen Zhang, Ze-Yu Zhang, Kai-Wei ZhangAI Agent Security BenchmarksPrompt Injection Defense

  16. When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

    Aug 1, 2026Neha Nagaraja, Amisha Bagari, Hayretdin BahsiMulti-Agent LLM SystemsLarge Language Model-Based Robot Planning

  17. Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure

    Aug 1, 2026Jianshuo Dong, Yiming Liu, Maosen Zhang +6Indirect Prompt InjectionPrompt Injection Defense

  18. Tool Specifications Matter: Uncovering and Mitigating Safety Risks in AI Agents

    Jul 31, 2026Minghui Pan, Jiayuxuan Yang, Yuanyuan Yuan +2LLM GuardrailsPrompt Injection Attacks on AI Agents

  19. GPT-Red: Automated Red Teaming via Self-Play at Scale

    Jul 28, 2026Eric Wallace, Christopher A. Choquette-Choo, Nikhil Kandpal +15Adversarial TrainingLLM Red Teaming

  20. SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems

    Jul 28, 2026Haowen Dai, Zonghao Ying, Wenfeng Li +10AI Agent SafetyInformation Flow Control

  21. Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents

    Jul 27, 2026Arseny Kravchenko, Vadim Liventsev, Innokentii Konstantinov +2LLM Agent SecurityPrompt Injection Attacks on AI Agents

  22. Where Is the Cost of Third-Party API Routers in Agentic Software Development?

    Jul 26, 2026Donghao Fu, Jingxin Li, Xue Jiang +1Coding AgentsAI Agent Security

  23. Agent Security Needs Redefinition through a Holistic Framework

    Jul 24, 2026Vincent Siu, Jingxuan He, Kyle Montgomery +3AI Agent SecurityAI Agent Security Benchmarks

  24. Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents

    Jul 22, 2026Or Zion Eliav, Eyal Lenga, Shir Bernstien +1AI Agent SecurityAI Agent Security Benchmarks

  25. Twin Agent: Context Residual Compression for Privilege Separated Agents

    Jul 21, 2026Zhanhao Hu, Dennis Jacob, Xiao Huang +3AI Agent SecurityLLM Agent Security

  26. ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems

    Jul 20, 2026Elias Hossain, Md Mehedi Hasan Nipu, Fatema Tuj Johora Faria +2LLM Agent SecurityPrompt Injection Attacks on AI Agents

  27. Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems

    Jul 16, 2026Soham Gadgil, David Alexander, Sai Sunku +1AI Agent SecurityAgent Memory Poisoning