研究者提出 Repeat-After-Me 黑盒自适应视觉提示注入攻击
AI 导读
研究者提出 Repeat-After-Me,一种黑盒自适应视觉提示注入方法,攻击者把指令隐藏在图片中,智能体读取后执行,导致 PII 泄露或调用恶意工具。作者称这是首个黑盒自适应视觉提示注入,论文见 https://arxiv.org/pdf/2609.04533。
相关论文
正文
Prompt injection doesn't have to be text. We introduce Repeat-After-Me — the first black-box adaptive visual prompt injection. An attacker hides instructions inside an image. The agent reads them, follows them, and leaks your PII or calls a malicious tool.
https://arxiv.org/pdf/2609.04533