ECLIPSE: Self-Evolving Stealthy Prompt Injection Attack against Long-Horizon Agentic Systems
cs.CR
Submitted: 2026-08-31
Updated: 2026-09-06
Terminology
Sources
- SecAlign: Defending Against Prompt Injection with Preference Optimization
- Are AI-assisted Development Tools Immune to Prompt Injection?
- SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
- AgentLAB: Benchmarking LLM Agents against Long-Horizon Attacks
- MemGPT: Towards LLMs as Operating Systems
- MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
- Ignore Previous Prompt: Attack Techniques For Language Models
- AgentDoG: A Diagnostic Guardrail Framework for AI Agent Safety and Security
- Hidden in Memory: Sleeper Memory Poisoning in LLM Agents
- WebTrap: Stealthy Mid-Task Hijacking of Browser Agents During Navigation
- Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections
- Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
- Prompt Injection Attack to Tool Selection in LLM Agents
- Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning
- LLaMA: Open and Efficient Foundation Language Models
- AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
- Voyager: An Open-Ended Embodied Agent with Large Language Models
- When Skills Lie: Hidden-Comment Injection in LLM Agents
- ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
- Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs