August 2026Unreviewed
StepJack: Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection
Zhuoxin Zhan, Akbar Rafiey, Avery Ma, Leila Pishdad, Layla El Asri
Abstract
Computer-use agents (CUAs) face a growing threat from indirect prompt injection, where adversarial instructions are planted in the environment such as web pages. In this paper, we introduce multi-step indirect prompt injection, a new attack class against CUAs in which the adversarial goal is decomposed into multiple innocuous-looking sub-steps and distributed across a chain of pages referenced along the agent's navigation path. We develop a pipeline to automatically decompose an adversarial goal
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{zhan2026stepjack,
title = {{StepJack: Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection}},
author = {Zhuoxin Zhan and Akbar Rafiey and Avery Ma and Leila Pishdad and Layla El Asri},
year = {2026},
month = aug,
eprint = {2608.06477},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.06477}
}