← Back to search
paper llmsec-2026-00098

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection

Chia-Pei, Chen, Kentaroh Toyoda, Anita Lai, Alex Leung

2026-05

Abstract

Web-browsing AI agents are increasingly deployed in enterprise settings under strict whitelists of approved domains, yet adversaries can still influence them by embedding hidden instructions in the HTML pages those domains serve. Existing red-teaming resources fall short of this scenario: prompt-injection benchmarks ship pre-built adversarial pages that whitelisted agents cannot reach, and generic LLM scanners probe the model API rather than its retrieved content. We present IPI-proxy, an open-s

Cite This Resource

@article{llmsec202600098,
  title = {IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection},
  author = { Chia-Pei and  Chen and Kentaroh Toyoda and Anita Lai and Alex Leung},
  year = {2026},
  url = {https://arxiv.org/abs/2605.11868},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.11868