Skip to content
Search
paperJune 2026Unreviewed

MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents

Xuelong Dai, Jianyu Ma, Boyang Ma, Biwei Yan, Yijun Yang, Yue Zhang

Abstract

Multimodal Large Language Model (MLLM)-based web agents provide practical, high-precision solutions for visual browser automation; however, they inherently expand the attack surface, introducing novel vision-based vulnerabilities. Existing adversarial evaluations targeting these agents frequently rely on permissive threat models and visually conspicuous artifacts. In this paper, we investigate a constrained vulnerability detection setting: a trusted web platform where the evaluator acts solely a

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{dai2026mirage,
  title = {{MIRAGE: Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents}},
  author = {Xuelong Dai and Jianyu Ma and Boyang Ma and Biwei Yan and Yijun Yang and Yue Zhang},
  year = {2026},
  month = jun,
  eprint = {2606.20717},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.20717}
}