Sahar Abdelnabi

h-index: 3 43 citations 8 papers (total)

Papers in Database (4)

attack arXiv Oct 30, 2025 · Oct 2025

Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections

David Schmotz, Sahar Abdelnabi, Maksym Andriushchenko · ELLIS Institute Tübingen · MPI for Intelligent Systems +1 more

Exploits LLM Agent Skills plugin framework for trivial indirect prompt injection, exfiltrating files and bypassing Claude Code guardrails

Prompt Injection Insecure Plugin Design nlp
8 citations 1 influentialPDF Code
benchmark arXiv Nov 7, 2025 · Nov 2025

ConVerse: Benchmarking Contextual Safety in Agent-to-Agent Conversations

Amr Gomaa, Ahmed Salem, Sahar Abdelnabi · German Research Center for Artificial Intelligence · Microsoft +3 more

Benchmarks privacy leakage and prompt-injection-style attacks across 864 multi-turn agent-to-agent LLM conversations in three domains

Prompt Injection Sensitive Information Disclosure nlp
5 citations 2 influentialPDF Code
benchmark arXiv Feb 23, 2026 · 6w ago

Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

David Schmotz, Luca Beurer-Kellner, Sahar Abdelnabi et al. · Max Planck Institute for Intelligent Systems · Snyk

Benchmarks LLM agent susceptibility to skill-file prompt injection, finding up to 80% attack success on frontier models

Prompt Injection Insecure Plugin Design nlp
PDF Code
attack arXiv Feb 9, 2026 · 8w ago

Stateless Yet Not Forgetful: Implicit Memory as a Hidden Channel in LLMs

Ahmed Salem, Andrew Paverd, Sahar Abdelnabi · Microsoft Security Response Center · ELLIS Institute Tübingen and MPI for Intelligent Systems +1 more

Introduces implicit memory as a hidden LLM channel enabling temporal backdoors that activate across sequences of independent interactions

Model Poisoning Prompt Injection nlp
PDF Code