July 2026Unreviewed
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents
Wenhao Lan, Shan Li, Xinhua Lai, Meiqi Wu, Junbin Yang, Haihua Shen
Abstract
Tool-using LLM agents process untrusted content, maintain memory, delegate across agents, and invoke side-effecting tools. Existing prompt-injection evaluations typically summarize security with terminal attack or policy outcomes, but equal endpoints can conceal different post-exposure traces and different losses of authorized utility. We introduce ContainmentBench, a sandboxed, trace-based benchmark that separately measures benchmark-defined endpoint policy compliance, instrumented logged propa
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{lan2026containmentbench,
title = {{ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents}},
author = {Wenhao Lan and Shan Li and Xinhua Lai and Meiqi Wu and Junbin Yang and Haihua Shen},
year = {2026},
month = jul,
eprint = {2607.23999},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.23999}
}