A Large-scale Measurement of In-Page Prompt Injections Against LLM Web Agents
Soheil Khodayari, Xuenan Zhang, Bhupendra Acharya, Giancarlo Pellegrino
Abstract
LLM web agents increasingly rely on web content as input, exposing them to indirect prompt injection embedded in webpages. While prior work has shown such attacks in controlled settings, it remains unclear whether prompt injection is already deployed in the wild and what role it plays in the web ecosystem. In this paper, we conduct the first large-scale empirical study of in-page prompt injection. Analyzing 1.2B URLs across 24.8M hosts, we identify 15.3K validated prompt injections, with a small set of reused templates accounting for the majority of cases.
Our analysis reveals a multi-stakeholder phenomenon, with injections serving diverse offensive and defensive objectives, including system disruption, reputation manipulation, data protection, and AI bot detection, and target a range of agents from web crawlers and search systems to customer-support and HR automation pipelines. Most injections (70%) are delivered in non-visible channels like HTTP headers, JS comments, or HTML-embedded hidden content. We assess their effectiveness through 5,200 systematic experiments across 13 models and four page representations, observing up to 8% effectiveness for smaller models on plain-text inputs, with lower effectiveness for other representations. Overall, our results show that in-page prompt injection is emerging as an important source of friction between LLM-based agents and the broader web ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c6251430-d09f-4438-bcf8-075d2b150587Builds on26
- BART: Denoising Sequence-to-Sequence Pre-training for Natural Language Generation, Translation, and ComprehensionMike Lewis, Yinhan Liu, Naman Goyal, Marjan Ghazvininejad et al.ACL 2020 · 1,224 citations
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia et al.USENIX Security 2024 · 308 citations
- SneakyPrompt: Jailbreaking Text-to-image Generative ModelsYuchen Yang, Bo Hui, Haolin Yuan, Neil Gong et al.S&P 2024 · 188 citations
- Prompt Injection Attack to Tool Selection in LLM AgentsJiawen Shi, Zenghui Yuan, Guiyao Tie, Pan Zhou et al.NDSS 2026 · 181 citations
Related papers
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsYigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann et al.S&P 2026 · 12 citations
- AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web AgentsYongbi Son, Changoo Lee, Dongwon Shin, Byoungyoung Lee et al.ISSTA 2026
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection AttacksGeorgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer et al.USENIX Security 2026 · 18 citations
- WebInject: Prompt Injection Attack to Web AgentsXilong Wang, John Bloch, Zedian Shao, Yuepeng Hu et al.EMNLP 2025 · 1 citation
- It's a TRAP! Task-Redirecting Agent Persuasion Benchmark for Web AgentsKarolina Korgul, Yushi Yang, Arkadiusz Drohomirecki, Piotr Blaszczyk et al.ICML 2026 · 8 citations
