Research · curated 9 Aug 2026
Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-World Web Agents
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
StakeBench shows that real-world LLM web agents transacting with untrusted web content remain broadly vulnerable to prompt injection with asymmetric harms across users, sellers, and platforms, giving defenders a way to measure victim-dependent risk.
StakeBench is a stakeholder-centric benchmark for evaluating prompt-injection risk in LLM-based web agents used for online shopping, decomposing risk into 12 attack objectives across User, Seller, and Platform stakeholder classes via 22 templates and 264 executable adversarial cases. Evaluating four deployable agent-backbone configurations across 3,168 attacked runs, the authors find no attack objective is reliably resisted, with outcomes spanning robust behavior, stealthy parasitism, misaligned disruption, and compounded failure.