TheMachine Press

A daily newspaper for the age of artificial intelligence.

Morning editionPermanent story

safety security

The Attacker Spent More Compute Searching the Environment

An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.

Published Updated Story ID: mp-2026-09-07-026
Read the complete editionStory JSON

Summary

An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.

The attacker first reconnoiters the environment, manages candidate strategies and uses victim-agent feedback to refine attempts. Across heterogeneous tasks, more test-time compute improved vulnerability discovery and exploitation, while removing explicit strategy management increased redundant search and weakened gains at higher budgets. The paper argues that evaluations should report attacker search procedure and compute budget instead of treating success as a fixed property of the victim. The evidence measures the tested harnesses and tasks, not every tool-using agent.

Why it matters

An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.

Limits and context

  • The evidence measures the tested harnesses and tasks, not every tool-using agent.

Key claims

  1. An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.

    Qualification: The evidence measures the tested harnesses and tasks, not every tool-using agent.

    Evidence: source-2026-09-07-015

Sources

  1. arXiv preprint 2609.04495arXiv · primary research

Corrections

No corrections have been recorded for this story.