Research · curated 9 Aug 2026

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-World Web Agents

Coverage timeline

9 Aug 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

StakeBench shows that real-world LLM web agents transacting with untrusted web content remain broadly vulnerable to prompt injection with asymmetric harms across users, sellers, and platforms, giving defenders a way to measure victim-dependent risk.

StakeBench is a stakeholder-centric benchmark for evaluating prompt-injection risk in LLM-based web agents used for online shopping, decomposing risk into 12 attack objectives across User, Seller, and Platform stakeholder classes via 22 templates and 264 executable adversarial cases. Evaluating four deployable agent-backbone configurations across 3,168 attacked runs, the authors find no attack objective is reliably resisted, with outcomes spanning robust behavior, stealthy parasitism, misaligned disruption, and compounded failure.