June 2026Unreviewed
Assessing Automated Prompt Injection Attacks in Agentic Environments
David Hofer, Edoardo Debenedetti, Florian Tramèr
Abstract
Indirect prompt injection poses a critical threat to LLM agents that interact with untrusted external data, yet automated attack methods--proven effective for jailbreaking--remain underexplored in realistic agentic settings. We present a comprehensive empirical evaluation of automated prompt injection attacks against LLM agents, adapting both white-box (GCG) and black-box (TAP) methods to the agentic setting within the AgentDojo framework. We evaluate across 80 task pairs spanning four domains a
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{hofer2026assessing,
title = {{Assessing Automated Prompt Injection Attacks in Agentic Environments}},
author = {David Hofer and Edoardo Debenedetti and Florian Tramèr},
year = {2026},
month = jun,
eprint = {2606.10525},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.10525}
}