PaperScope
LIVE · 2026-10-06 05:40 UTC

Who Is Your Agent Serving? Provider-Side Indirect Prompt Injection in Proactive Agents

Rui Wang, Chao Wang, Xinchen Wang, Yufeng Zheng, Binbin Liu, Yaofei Wang

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2610.05266 v1
Category
Submitted
2026-10-04

Abstract

Proactive personal agents increasingly decide what to recommend, how to personalize advice, and what follow-up assistance to offer, creating a new user-decision attack surface for provider-side indirect prompt injection. We show that an external provider need not access private user context, compromise the agent, or gain additional permissions: by controlling only content associated with its own target, it can redirect an otherwise benign agent to advance that target, recruit legitimately available user context to justify it, and proactively reduce the friction of adoption. We characterize this failure mode through Target Control, Private Binding, and Prospective Support, which respectively steer what the agent advances, how it connects the target to the user, and what target-specific assistance it offers next. Across three proactive-agent environments and six simulated user models, the full attack increases target authorization in all tested environment-user-model combinations, with a macro gain of up to 77.4 percentage points. Controlled replay shows that correct user-target binding is more consequential than additional proposal detail alone, while a multi-turn extension reveals that provider objectives can remain influential even without final authorization by reshaping how the agent responds to user constraints and resistance. These findings expose a broader trust boundary: capabilities designed to serve the user can be redirected toward objectives originating outside the user-agent relationship.

Comment: 30 pages, 7 figures, 13 tables

arXiv abs page · PDF · same-day batch