safety security
The Attacker Spent More Compute Searching the Environment
An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.
Summary
An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.
The attacker first reconnoiters the environment, manages candidate strategies and uses victim-agent feedback to refine attempts. Across heterogeneous tasks, more test-time compute improved vulnerability discovery and exploitation, while removing explicit strategy management increased redundant search and weakened gains at higher budgets. The paper argues that evaluations should report attacker search procedure and compute budget instead of treating success as a fixed property of the victim. The evidence measures the tested harnesses and tasks, not every tool-using agent.
Why it matters
An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.
Limits and context
- The evidence measures the tested harnesses and tasks, not every tool-using agent.
Key claims
An agentic red-team harness treats indirect prompt injection as adaptive test-time search over the user task, environment and attack goal.
Qualification: The evidence measures the tested harnesses and tasks, not every tool-using agent.
Evidence: source-2026-09-07-015
Sources
- arXiv preprint 2609.04495arXiv · primary research
Corrections
No corrections have been recorded for this story.