Skip to content
Search
paperAugust 2026Unreviewed

Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents

Yunseok Lee, Yunji Kim, Woojin Lee

Abstract

As LLM agents take real-world actions through tools, indirect prompt injection (IPI) has emerged as a serious threat. The standard metric, Attack Success Rate (ASR), counts whether an injection succeeds but ignores what the user notices in the agent's final response. Looking at successful injection traces, we find two distinct outcomes: the agent executes the injection while returning an otherwise normal response, or reports the injected action in its final response, giving the user a chance to

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{lee2026will,
  title = {{Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents}},
  author = {Yunseok Lee and Yunji Kim and Woojin Lee},
  year = {2026},
  month = aug,
  eprint = {2608.30362},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.30362}
}