כתבה
arXiv cs.AI ·
Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents
תקציר מקורי באנגליתarXiv:2608.30362v3 Announce Type: replace Abstract: As LLM agents take real-world actions through tools, indirect prompt injection (IPI) has emerged as a serious threat. The standard metric, Attack Success Rate (ASR), counts whether an injection succeeds but ignores what the user notices in the agent's final response. Looking at successful injection traces, we find two distinct outcomes: the agent executes the injection while returning an otherwise normal response, or reports the injected action in its final response, giving the user a chance to notice. We call these covert and overt successes. From the user's perspective, we decompose ASR into the Covert Success Rate (CSR), counting successes leaving no trace in the final response, and the Overt Success Rate (OSR), counting successes the
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית