Skip to content
Search
paperMay 2026Unreviewed

Blind Spots in the Guard: How Domain-Camouflaged Injection Attacks Evade Detection in Multi-Agent LLM Systems

Aaditya Pai

Abstract

Injection detectors deployed to protect LLM agents are calibrated on static, template-based payloads that announce themselves as override directives. We identify a systematic blind spot: when payloads are generated to mimic the domain vocabulary and authority structures of the target document, what we call domain camouflaged injection, standard detectors fail to flag them, with detection rates dropping from 93.8% to 9.7% on Llama 3.1 8B and from 100% to 55.6% on Gemini 2.0 Flash. We formalize th

Categories

Cite

@misc{pai2026blind,
  title = {{Blind Spots in the Guard: How Domain-Camouflaged Injection Attacks Evade Detection in Multi-Agent LLM Systems}},
  author = {Aaditya Pai},
  year = {2026},
  month = may,
  eprint = {2605.22001},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.22001}
}