Skip to content
Search
paperApril 2026Unreviewed

WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents

Yulin Chen, Tri Cao, Haoran Li, Yue Liu, Yibo Li, Yufei He, Le Minh Khoi, Yangqiu Song, Shuicheng Yan, Bryan Hooi

Abstract

Web agents powered by vision-language models (VLMs) enable autonomous interaction with web environments by perceiving and acting on both visual and textual webpage content to accomplish user-specified tasks. However, they are highly vulnerable to prompt injection attacks, where adversarial instructions embedded in HTML or rendered screenshots can manipulate agent behavior and lead to harmful outcomes such as information leakage. Existing defenses, including system prompt defenses and direct fine

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{chen2026webagentguard,
  title = {{WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents}},
  author = {Yulin Chen and Tri Cao and Haoran Li and Yue Liu and Yibo Li and Yufei He and Le Minh Khoi and Yangqiu Song and Shuicheng Yan and Bryan Hooi},
  year = {2026},
  month = apr,
  eprint = {2604.12284},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.12284}
}