כתבה
arXiv cs.AI ·
DualView: מניעת הזרקת תבניות פתוחות באג'נטים אישיים
DualView: Preventing Indirect Prompt Injection in Personal AI Agents
DualView מניעה הזרקת תבניות פתוחות באג'נטים אישיים. חידוש זה חשוב למניעת פגיעה בביטחון של האג'נט. DualView ניתן להפעלה כתוספת ל-OpenClaw.
תקציר מקורי באנגליתarXiv:2607.03821v2 Announce Type: replace-cross Abstract: Personal AI agents that run on the user's local machine automate daily tasks including web search, email, and file management. Their access to computer resources, including the network, file system, and shell, exposes them to indirect prompt injection (IPI) attacks. Prior Dual LLM defenses block IPI by replacing untrusted data with symbols that the agent can reference but not read. However, they track untrusted data only inside the agent's context, so when the agent saves and later rereads untrusted data, that data, possibly an attacker's prompt, can return as trusted data rather than as a symbol, which we call stored IPI. Operating on the user's real environment is what makes agents like OpenClaw practical, and is exactly why a def
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית