September 2026Unreviewed
Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection
Sizhe Chen, Yu-Lin Tsai, Ivan Evtimov, Kamalika Chaudhuri, Raluca Ada Popa, David Wagner, Arman Zharmagambetov
Abstract
Prompt injection is widely recognized as a major security threat to AI agents that interact with untrusted external data, such as websites, documents, and emails. Prior work has shown that, in the text domain, black-box prompt injection can achieve near-perfect attack success rates (ASRs). In the image domain, however, existing visual prompt injection methods are substantially less effective in attacking frontier commercial VLMs for materially harmful behavior. Achieving such outputs is hard bec
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{chen2026repeatafterme,
title = {{Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection}},
author = {Sizhe Chen and Yu-Lin Tsai and Ivan Evtimov and Kamalika Chaudhuri and Raluca Ada Popa and David Wagner and Arman Zharmagambetov},
year = {2026},
month = sep,
eprint = {2609.04533},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.04533}
}