יום שלישי, 15 בספטמבר 2026 LIVE
AI־INFO

כתבה arXiv cs.AI ·

חשוב מחדש: הזרקת תרגום ישיר/בלתי ישיר כבעיה של חיפוש בזמן המבחן

Rethinking Indirect Prompt Injection as a Test-Time Search Problem
ניסיון להגדיר זרקת תרגום ישיר/בלתי ישיר כבעיה של חיפוש בזמן המבחן, ולפתח תכנית תקיפה שתפעל באופן רב-שלבי.
תקציר מקורי באנגליתarXiv:2609.04495v1 Announce Type: new Abstract: We formulate indirect prompt injection as a test-time search over a task-dependent attack surface induced by the environment, user task, and injection task. To operationalize this formulation, we introduce an agentic attacker with a dedicated search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. Across heterogeneous tasks, we find that increasing attacker test-time compute improves vulnerability discovery and exploitation, while ablations show that explicit strategy management is important for avoiding redundant search and sustaining gains at larger budgets. These results suggest that agentic security evaluations should characterize both the a
קרא במקור המקורי