August 2026Unreviewed
Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents
Yunseok Lee, Yunji Kim, Woojin Lee
Abstract
As LLM agents take real-world actions through tools, indirect prompt injection (IPI) has emerged as a serious threat. The standard metric, Attack Success Rate (ASR), counts whether an injection succeeds but ignores what the user notices in the agent's final response. Looking at successful injection traces, we find two distinct outcomes: the agent executes the injection while returning an otherwise normal response, or reports the injected action in its final response, giving the user a chance to
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{lee2026will,
title = {{Will the User Ever Know? Covert Indirect Prompt Injection Attacks on Tool-Using LLM Agents}},
author = {Yunseok Lee and Yunji Kim and Woojin Lee},
year = {2026},
month = aug,
eprint = {2608.30362},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.30362}
}