arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

超越有效载荷:用户调用如何塑造编码代理对仓库中毒的漏洞

Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning

Fukang Zhu, Binbin Zhao, Ruixiao Lin, Ping He, Tianyu Du, Shouling Ji

arXiv 2608.30686首次发表:更新:

发表机构

Zhejiang University; Tsinghua University(浙江大学; 清华大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究推出首个针对编码代理仓库中毒漏洞的基准CIPR,发现漏洞高度依赖用户提示级配置,任务类型可使攻击成功率产生4.5倍差异,测试执行任务为隐蔽攻击面,不明确或嘈杂提示会间接改变风险。

AI 中文摘要

编码代理越来越多地用于软件工程任务,包括从完整性无法保证的第三方仓库启动项目。先前关于仓库中毒的研究主要关注攻击者控制的注入与伪装,但开发者也会通过日常调用选择塑造风险:委托的任务类型、请求的表述方式、提供的技能或规则。我们将这些用户侧选择称为提示级配置(PLCs),并推出首个系统改变中毒真实仓库中PLCs的基准CIPR(Coding In Poisoned Repos)。CIPR包含20个仓库、4种任务类型、3种社交媒体风格提示、3种技能/规则条件下的1920个实例,通过自动运行时和基于跟踪的预言机测量攻击成功率(ASR)与代理告警率(AR)。评估揭示两个关键见解:(1)漏洞高度依赖上下文,任务类型使ASR产生最高达4.5倍的差异,其中测试执行任务形成隐蔽攻击面(高ASR、低AR);(2)提示表述间接改变风险:不明确的提示通过截断执行深度降低ASR,嘈杂提示则因恶意内容不那么显眼而呈现抑制告警的趋势。这些发现表明,编码代理的漏洞并非静态属性,而是日常用户配置塑造的动态结果。

英文摘要

Coding agents are increasingly used for software engineering tasks, including bootstrapping projects from third-party repositories whose integrity cannot be assumed. Prior work on repository poisoning largely focuses on attacker-controlled injection and disguise, but developers also shape risk through everyday invocation choices: what task to delegate, how to phrase the request, and which skills or rules to supply. We term these user-side choices Prompt-Level Configurations (PLCs) and introduce CIPR (Coding In Poisoned Repos), the first benchmark that systematically varies PLCs in poisoned real-world repositories. CIPR comprises 1,920 instances across 20 repositories, four task types, three social-media-grounded prompt styles, and three skill/rule conditions, and measures attack success rate (ASR) and agent alert rate (AR) using automated runtime and trace-based oracles. Our evaluation reveals two key insights: (1) Vulnerability is highly context-dependent, with task type creating up to a 4.5-fold difference in ASR, with test-execution task forming a silent attack surface (high ASR, low AR). (2) Prompt expression shifts risk indirectly: underspecified prompts reduce ASR by truncating execution depth; noisy prompts exhibit a directional trend toward suppressing alerts by making malicious content less conspicuous. These findings highlight that coding agent vulnerability is not a static property, but a dynamic outcome shaped by everyday user configurations.

Comments30 pages,7 figures, Accepted to EMNLP 2026 Main Conference

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑