ai-digest.dev
last updated 4 h ago
SafetyarXiv cs.AI 10 d ago

MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks

MUZZLE is an automated framework designed to evaluate the security of web agents against indirect prompt injection attacks, which exploit vulnerabilities in large language model (LLM) deployments. By leveraging the agent's execution trajectories, MUZZLE identifies high-risk injection surfaces and generates context-aware malicious instructions, adapting its attack strategies based on observed behaviors. This framework demonstrated its effectiveness by discovering 44 new attacks across four web applications, including novel strategies targeting confidentiality and availability, which highlights the need for dynamic security evaluations in LLM-based systems.

securityprompt injectionweb agentsrelevance 0.00 · engagement 0.00
Read at source ↗← all news
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks — AI News Digest