微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接。
Rethinking Indirect Prompt Injection as a Test-Time Search Problem
RSS 官方收录 · 可信分层展示
关键摘要
arXiv:2609.…
- 04495v1 Announce Type: new Abstract: We formulate indirect prompt inje…
- To operationalize this formulation, we introduce an agentic attacker w…
- Across heterogeneous tasks, we find that increasing attacker test-time…
规则摘要 · 来源可核验
正文提要
arXiv:2609.04495v1 Announce Type: new Abstract: We formulate indirect prompt injection as a test-time search over a task-dependent attack surface induced by the environment, user task, and injection task. To operationalize this formulation, we introduce an agentic attacker with a dedicated search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. Across heterogeneous tasks, we find that increasing attacker test-time compute improves vulnerability discovery and exploitation, while ablations show that explicit strategy management is important for avoiding redundant search and sustaining gains at larger budgets. These results suggest that agentic security evaluations should characterize both the attacker's search procedure and compute budget, rather than treating attack success as a budget-independent property of the victim. More broadly, our findings identify the attacker's adaptive search over the system attack surfaces as an important and underexplored security risk for tool-using agents.