将间接提示注入重新思考为测试时搜索问题
Rethinking Indirect Prompt Injection as a Test-Time Search Problem
浏览论文内容
中文总结 AI 辅助
该研究将间接提示注入视为测试时搜索问题,提出带专用搜索工具的智能体攻击者,发现增加测试时计算量可提升漏洞利用能力,显式策略管理很重要,强调需评估攻击者的搜索过程与计算预算。
中文摘要 AI 辅助
我们将间接提示注入问题表述为针对由环境、用户任务和注入任务诱导的任务相关攻击面的测试时搜索。为实现该表述,我们引入了一种具有专用搜索工具的智能体攻击者,该工具可执行环境侦察、对攻击策略进行结构化推理,并利用受害智能体的反馈进行自适应评估。在不同任务中,我们发现增加攻击者的测试时计算量可提升漏洞的发现与利用能力;而消融实验表明,显式策略管理对避免冗余搜索及在更大预算下维持收益至关重要。这些结果表明,智能体安全评估应同时刻画攻击者的搜索过程与计算预算,而非将攻击成功视为与预算无关的受害智能体属性。更广泛而言,我们的研究结果指出,攻击者对系统攻击面的自适应搜索是使用工具的智能体面临的一项重要且未被充分探索的安全风险。
英文摘要
We formulate indirect prompt injection as a test-time search over a task-dependent attack surface induced by the environment, user task, and injection task. To operationalize this formulation, we introduce an agentic attacker with a dedicated search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. Across heterogeneous tasks, we find that increasing attacker test-time compute improves vulnerability discovery and exploitation, while ablations show that explicit strategy management is important for avoiding redundant search and sustaining gains at larger budgets. These results suggest that agentic security evaluations should characterize both the attacker's search procedure and compute budget, rather than treating attack success as a budget-independent property of the victim. More broadly, our findings identify the attacker's adaptive search over the system attack surfaces as an important and underexplored security risk for tool-using agents.
发表机构
- Dynamo AI
- University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)
机构由 AI 辅助整理,请以论文原文为准。