Skip to main content
Aggregate AI 摘要 arXiv cs.AI 人工智能 7 Sep 2026 - 13:00

Rethinking Indirect Prompt Injection as a Test-Time Search Problem

RSS 官方收录 · 可信分层展示

关键摘要

将间接提示注入重新定义为测试时搜索问题,揭示工具型AI新安全风险

  • 提出间接提示注入是任务相关攻击面的测试时搜索问题
  • 设计具备环境侦察与策略推理能力的智能攻击者
  • 发现攻击者计算预算增加会提升漏洞发现与利用效果

AI 摘要 · 来源可核验

正文提要

arXiv:2609.04495v1 Announce Type: new Abstract: We formulate indirect prompt injection as a test-time search over a task-dependent attack surface induced by the environment, user task, and injection task. To operationalize this formulation, we introduce an agentic attacker with a dedicated search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. Across heterogeneous tasks, we find that increasing attacker test-time compute improves vulnerability discovery and exploitation, while ablations show that explicit strategy management is important for avoiding redundant search and sustaining gains at larger budgets. These results suggest that agentic security evaluations should characterize both the attacker's search procedure and compute budget, rather than treating attack success as a budget-independent property of the victim. More broadly, our findings identify the attacker's adaptive search over the system attack surfaces as an important and underexplored security risk for tool-using agents.

来源:https://arxiv.org/abs/2609.04495

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表