Research · curated 13 Sep 2026

Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection

Coverage timeline

13 Sep 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Visual prompt injection that reliably produces format-compliant malicious tool calls extends the prompt-injection threat surface to any AI agent that processes untrusted images, defeating cases where textual injection fails.

The paper 'Repeat-After-Me' presents a black-box adaptive visual prompt injection attack against frontier vision-language models, embedding malicious instructions in images to leak personally identifiable information or trigger malicious native tool calls. The authors report attack success rates exceeding 80% on open-weight models and 47% on commercial VLMs, with meaningful cross-model and cross-sample transferability, and demonstrate overwriting a tool configuration in a real agent deployment to enable follow-on RCE and secret exfiltration.