February 2026Unreviewed
AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System
Hao Li, Ruoyao Wen, Shanghao Shi, Ning Zhang, Chaowei Xiao
arXiv.org
Abstract
AI agents that autonomously interact with external tools and environments show great promise across real-world applications. However, the external data which agent consumes also leads to the risk of indirect prompt injection attacks, where malicious instructions embedded in third-party content hijack agent behavior. Guided by benchmarks, such as AgentDojo, there has been significant amount of progress in developing defense against the said attacks. As the technology continues to mature, and that
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{li2026agentdyn,
title = {{AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System}},
author = {Hao Li and Ruoyao Wen and Shanghao Shi and Ning Zhang and Chaowei Xiao},
year = {2026},
month = feb,
eprint = {2602.03117},
archivePrefix = {arXiv},
doi = {10.48550/arXiv.2602.03117},
url = {https://www.semanticscholar.org/paper/a2503b39343272c8ae4eebc9b41174c8d4876a0b}
}