Research · curated 21 Sep 2026
Rethinking Indirect Prompt Injection as a Test-Time Search Problem
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The paper reframes attack success against tool-using agents as dependent on the attacker's adaptive search and compute budget, meaning defenders cannot treat vulnerability as a fixed property of the victim agent and must account for well-resourced adaptive adversaries.
A research paper titled "Rethinking Indirect Prompt Injection as a Test-Time Search Problem" formulates indirect prompt injection against tool-using agents as a test-time search over a task-dependent attack surface, introducing an agentic attacker with a search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. The authors find that increasing attacker test-time compute improves vulnerability discovery and exploitation, and that explicit strategy management sustains gains at larger budgets.