Skip to content
Search
paperJune 2026Unreviewed

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents

Zihao Wang, Yiming Li, Yutong Wu, Zheyu Liu, Kangjie Chen, Fok Kar Wai, Pin-Yu Chen, Vrizlynn L. L. Thing, Bo Li, Dacheng Tao, Tianwei Zhang

Abstract

Web agents driven by large language models (LLMs) are increasingly deployed in real-world environments, where they operate over untrusted web content and execute actions with direct consequences. This makes them vulnerable to prompt-injection attacks, in which seemingly benign content embeds adversarial instructions that manipulate agent behaviour. Existing security benchmarks adopt an \textit{attack-centric} perspective, focusing on the technical feasibility of injections while overlooking the

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{wang2026who,
  title = {{Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents}},
  author = {Zihao Wang and Yiming Li and Yutong Wu and Zheyu Liu and Kangjie Chen and Fok Kar Wai and Pin-Yu Chen and Vrizlynn L. L. Thing and Bo Li and Dacheng Tao and Tianwei Zhang},
  year = {2026},
  month = jun,
  eprint = {2606.13385},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.13385}
}