September 2026Unreviewed
An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI Frameworks
Viet K. Nguyen, Mohammad I. Husain
Abstract
Agentic AI frameworks let a language model plan, keep memory, and call tools that reach real files, mail, and services. Most of these agents also read images, which gives an attacker a way to put text into the agent's context without going through the user. We present MMPIBench, a reproducible benchmark that measures what happens next. It delivers a fixed set of attacks through six visual carriers (OCR text, overlays, EXIF metadata, QR codes, fake interfaces, and hybrids) and records how far eac
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{nguyen2026experimental,
title = {{An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI Frameworks}},
author = {Viet K. Nguyen and Mohammad I. Husain},
year = {2026},
month = sep,
eprint = {2609.09404},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.09404}
}