WebInject: Prompt Injection Attack to Web Agents
Xilong Wang, John Bloch, Zedian Shao, Yuepeng Hu, Shuyan Zhou, Neil Zhenqiang Gong
摘要
Multi-modal large language model (MLLM)-based web agents interact with webpage environments by generating actions based on screenshots of the webpages. In this work, we propose WebInject, a prompt injection attack that manipulates the webpage environment to induce a web agent to perform an attacker-specified action. Our attack adds a perturbation to the raw pixel values of the rendered webpage. After these perturbed pixels are mapped into a screenshot, the perturbation induces the web agent to perform the attacker-specified action. We formulate the task of finding the perturbation as an optimization problem. A key challenge in solving this problem is that the mapping between raw pixel values and screenshot is non-differentiable, making it difficult to backpropagate gradients to the perturbation. To overcome this, we train a neural network to approximate the mapping and apply projected gradient descent to solve the reformulated optimization problem. Extensive evaluation on multiple datasets shows that WebInject is highly effective and significantly outperforms baselines.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- VPI-Bench: Visual Prompt Injection Attacks for Computer-Use AgentsTri Cao, Bennett Lim, Yue Liu, Yuan Sui 等ICLR 2026 · 被引用 45 次
- PromptLocate: Localizing Prompt Injection AttacksYuqi Jia, Yupei Liu, Zedian Shao, Jinyuan Jia 等S&P 2026 · 被引用 35 次
- Measuring Real-World Prompt Injection Attacks in LLM-based Resume ScreeningMohan Zhang, Yuqi Jia, Zhen Tan, Steven Jiang 等USENIX Security 2026 · 被引用 4 次
- Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation EvaluationRabimba Karanjai, Yang Lu, Hemanth Hegadehalli Madhavarao, Lei Xu 等USENIX Security 2026 · 被引用 4 次
- Causal Detection of Multi-Step LLM Agent AttacksViraaji Mothukuri, Reza M. PariziICML 2026 · 被引用 2 次
它引用的顶会 Paper11
- GPT-4V(ision) is a Generalist Web Agent, if GroundedBoyuan Zheng, Boyu Gou, Jihyung Kil, Huan Sun 等ICML 2024 · 被引用 496 次
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia 等USENIX Security 2024 · 被引用 308 次
- Prompt Injection Attack to Tool Selection in LLM AgentsJiawen Shi, Zenghui Yuan, Guiyao Tie, Pan Zhou 等NDSS 2026 · 被引用 181 次
- Attacking Vision-Language Computer Agents via Pop-upsYanzhe Zhang, Tao Yu, Diyi YangACL 2025 · 被引用 99 次
- Optimization-based Prompt Injection Attack to LLM-as-a-JudgeJiawen Shi, Zenghui Yuan, Yinuo Liu, Yue Huang 等CCS 2024 · 被引用 33 次
相关 Paper
- Manipulating Multimodal Agents via Cross-Modal Prompt InjectionLe Wang, Zonghao Ying, Tianyuan Zhang, Siyuan Liang 等ACM MM 2025 · 被引用 8 次
- A Large-scale Measurement of In-Page Prompt Injections Against LLM Web AgentsSoheil Khodayari, Xuenan Zhang, Bhupendra Acharya, Giancarlo PellegrinoCCS 2026
- It's a TRAP! Task-Redirecting Agent Persuasion Benchmark for Web AgentsKarolina Korgul, Yushi Yang, Arkadiusz Drohomirecki, Piotr Blaszczyk 等ICML 2026 · 被引用 8 次
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection AttacksGeorgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer 等USENIX Security 2026 · 被引用 18 次
- AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web AgentsYongbi Son, Changoo Lee, Dongwon Shin, Byoungyoung Lee 等ISSTA 2026
