Skip to content
Search
paperAugust 2026Unreviewed

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure

Jianshuo Dong, Yiming Liu, Maosen Zhang, Nan Deng, Xu Peng, Xiaoping Zhang, Tianwei Zhang, Jie Zhang, Han Qiu

Abstract

Agentic LLMs are vulnerable to indirect prompt injection (IPI) attacks, e.g., malicious side-tasks hidden in external tool results. While many efforts have sought to address the threats, little is known about the internals of agentic LLMs when they are exposed to IPI attacks, a condition which we call IPI exposure. In this paper, we study this problem in depth from three aspects. (1) Probing: Across six models, including the giant 753B-parameter GLM-5.2, simple linear probes trained on pre-gener

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{dong2026your,
  title = {{Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure}},
  author = {Jianshuo Dong and Yiming Liu and Maosen Zhang and Nan Deng and Xu Peng and Xiaoping Zhang and Tianwei Zhang and Jie Zhang and Han Qiu},
  year = {2026},
  month = aug,
  eprint = {2608.02657},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.02657}
}