Latest papers

2 papers
defense arXiv Apr 7, 2026 · 6w ago

The Defense Trilemma: Why Prompt Injection Defense Wrappers Fail?

Manish Bhatt, Sarthak Munshi, Vineeth Sai Narajala et al. · OWASP · Amazon Web Services +3 more

Proves continuous utility-preserving prompt filters cannot eliminate all LLM jailbreaks due to topological constraints on prompt space

Prompt Injection nlp
PDF Code
attack arXiv Apr 3, 2026 · 6w ago

Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents

Wei Zou, Mingwen Dong, Miguel Romero Calvo et al. · Pennsylvania State University · Amazon Web Services

Memory poisoning attack on LLM web agents via contaminated webpage observations, achieving persistent cross-session compromise

Data Poisoning Attack Prompt Injection Excessive Agency nlpmultimodal
PDF