arXiv:2609.32691v1 Announce Type: new Abstract: LLM agents that invoke privileged tools are vulnerable to indirect prompt injection (IPI), in which adversarial instructions embedded in retrieved data hijack the agent's actions. A growing body of work evaluates defenses against IPI, but the validity of that evaluation is rarely examined.

Read the full article at arXiv cs.CR →