arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

编码智能体中的包幻觉攻击:通过规则文件中的提示注入

Package Hallucination Attacks on Coding Agents through Prompt Injection in Rule Files

Yupu Wang, Zhengyuan Jiang, Reachal Wang, Neil Zhenqiang Gong

arXiv 2610.09264首次发表:更新:

发表机构

Duke University(杜克大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对编码智能体依赖社区规则文件的漏洞,提出包幻觉攻击及进化优化框架PackHallu,通过注入恶意提示诱导替换依赖,实验证明高成功率与强迁移性,亟需加强安全防护。

AI 中文摘要

现代智能体编码框架越来越依赖社区共享的规则文件(例如 this http URL 或 .cursorrules)来指导自主代码生成,然而这一流程的安全风险仍未得到充分探索。为弥补这一空白,我们提出了包幻觉攻击,攻击者将恶意提示注入良性规则文件,以诱导编码智能体将合法依赖替换为攻击者控制的包。为获得注入规则文件的有效恶意提示,我们提出了 PackHallu,一种进化优化框架,它利用轨迹级反馈和 LLM 引导的变异迭代重写这些注入提示。在多个基准、LLM 和智能体框架上的评估表明,PackHallu 实现了高攻击成功率,并在不同模型和智能体组合间表现出强迁移性。我们的发现证明编码智能体易受包幻觉攻击,凸显了在自主编码系统中加强安全防护的紧迫性。

英文摘要

Modern agentic coding frameworks increasingly rely on community-shared rule files (e.g., AGENTS.md or .cursorrules) to guide autonomous code generation, yet the security risks of this pipeline remain underexplored. To bridge this gap, we introduce the package hallucination attack, where an attacker injects malicious prompts into benign rule files to induce coding agents to replace legitimate dependencies with attacker-controlled packages. To obtain effective malicious prompts injected into rule files, we propose PackHallu, an evolutionary optimization framework that iteratively rewrites these injected prompts using trajectory-level feedback and LLM-guided mutations. Evaluations across multiple benchmarks, LLMs, and agent frameworks show that PackHallu achieves high attack success rates and strong transferability across diverse models and agent combinations. Our findings demonstrate that coding agents are vulnerable to package hallucination attacks, highlighting the urgent need for stronger security safeguards in autonomous coding systems.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑