The Like Trap: Multi-Stage Poisoning against Agents in Similarity-based Recommendation Systems
cs.CR, cs.AI, cs.LG, stat.ML
Submitted: 2026-09-22
Updated: 2026-09-22
Code: https://github.com/taazkareem/twitter-mcp-server
Project page: https://t.co/ncPENKuiBd
Terminology
Sources
- PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections
- Towards Large-scale Generative Ranking
- Agent Privilege Separation in OpenClaw: A Structural Defense Against Prompt Injection
- Defeating Prompt Injections by Design
- Taming OpenClaw: Security Analysis and Mitigation of Autonomous LLM Agent Threats
- VIGIL: Defending LLM Agents Against Tool Stream Injection via Verify-Before-Commit
- Trojan's Whisper: Stealthy Manipulation of OpenClaw through Injected Bootstrapped Guidance
- How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
- OASIS: Open Agent Social Interaction Simulations with One Million Agents
- Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution
- Is Your LLM-as-a-Recommender Agent Trustable? LLMs' Recommendation is Easily Hacked by Biases (Preferences)
- MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs