Skip to content
Search
paperMay 2026Unreviewed

ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents

Udari Madhushani Sehwag, Zhengyang Shan, Heming Liu, Dileepa Lakshan, Joseph Brandifino, Max Fenkell

Abstract

Clarification-seeking behavior is widely regarded as a desirable property of LLM agents, enabling them to resolve ambiguity before acting on underspecified tasks. However, the security implications of this interaction pattern remain unexplored. We investigate whether the transition from standard execution to a clarification-seeking state increases an agent's susceptibility to prompt injection attacks. We introduce ASPI (Ambiguous-State Prompt Injection), a benchmark of 728 task-attack scenarios

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{sehwag2026aspi,
  title = {{ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents}},
  author = {Udari Madhushani Sehwag and Zhengyang Shan and Heming Liu and Dileepa Lakshan and Joseph Brandifino and Max Fenkell},
  year = {2026},
  month = may,
  eprint = {2605.17324},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.17324}
}