2 papers
cs.CR2026
DriftNet: A Dual-Head Trajectory Transformer for Detecting and Localizing Prompt Injection in LLM Agents
Asif Pinjari, Mithun Paul Saint-Germain
When an indirect prompt injection succeeds against an LLM agent, the compromise is visible in the agent's own behavior: a benign prefix of tool calls, a poisoned observation, and a…
cs.CR2026
AgentDrift: A Step-Labeled Benchmark of Injection-Hijacked LLM Agent Trajectories
Asif Pinjari, Mithun Paul Saint-Germain
LLM agents complete tasks by issuing sequences of tool calls, and every observation they read is a channel through which an indirect prompt injection can enter. A successful inject…