May 2026Unreviewed
ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents
Udari Madhushani Sehwag, Zhengyang Shan, Heming Liu, Dileepa Lakshan, Joseph Brandifino, Max Fenkell
Abstract
Clarification-seeking behavior is widely regarded as a desirable property of LLM agents, enabling them to resolve ambiguity before acting on underspecified tasks. However, the security implications of this interaction pattern remain unexplored. We investigate whether the transition from standard execution to a clarification-seeking state increases an agent's susceptibility to prompt injection attacks. We introduce ASPI (Ambiguous-State Prompt Injection), a benchmark of 728 task-attack scenarios
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{sehwag2026aspi,
title = {{ASPI: Seeking Ambiguity Clarification Amplifies Prompt Injection Vulnerability in LLM Agents}},
author = {Udari Madhushani Sehwag and Zhengyang Shan and Heming Liu and Dileepa Lakshan and Joseph Brandifino and Max Fenkell},
year = {2026},
month = may,
eprint = {2605.17324},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.17324}
}