Agent 与自动化 5.0 · 必读 2026-06-03 · 论文

What If Prompt Injection Never Left? Rethinking Agent Security through Cross-Session Stored Prom...

论文提出跨会话存储型提示注入:外部信息进入智能体持久状态(记忆文件系统工具长生命周期上下文)后,恶意指令可长期潜伏并在后续会话静默生效,类似存储型 XSS;威胁模型在时间与空间两个维度扩展了提示注入的定义

打开原文回到归档

What If Prompt Injection Never Left? Rethinking Agent Security through Cross-Session Stored Prompt Injection

  • ID: b679220f
  • 原文链接: https://arxiv.org/abs/2606.04425
  • PDF: https://arxiv.org/pdf/2606.04425
  • 作者: Yuanbo Xie, Wenlei Zhu, Tianyun Liu, Yingjie Zhang, Suchen Liu, Yulin Li, Liya Su, Tingwen Liu
  • 日期: 2026-06-03
  • 更新: 2026-07-29
  • 分类: agents
  • 来源类型: arxiv
  • 标签: agent-security, prompt-injection, memory, arxiv
  • 质量评分: 5/5
  • 抓取时间: 2026-08-23T05:25:57Z

中文导读

论文提出跨会话存储型提示注入:外部信息进入智能体持久状态(记忆文件系统工具长生命周期上下文)后,恶意指令可长期潜伏并在后续会话静默生效,类似存储型 XSS;威胁模型在时间与空间两个维度扩展了提示注入的定义

为什么值得关注

论文提出跨会话存储型提示注入:外部信息进入智能体持久状态(记忆文件系统工具长生命周期上下文)后,恶意指令可长期潜伏并在后续会话静默生效,类似存储型 XSS;威胁模型在时间与空间两个维度扩展了提示注入的定义

Grounding: the paper formalizes the lifecycle of cross-session stored prompt injection, builds a taxonomy of persistence channels and incorporation mechanisms, and redefines prompt injection across both time and space for agentic systems with persistent state (memories, filesystems, tools, long-lived contextual artifacts).

关键信息

  • 论文标题: What If Prompt Injection Never Left? Rethinking Agent Security through Cross-Session Stored Prompt Injection
  • 作者: Yuanbo Xie, Wenlei Zhu, Tianyun Liu, Yingjie Zhang, Suchen Liu, Yulin Li, Liya Su, Tingwen Liu
  • arXiv: https://arxiv.org/abs/2606.04425
  • 发布时间: 2026-06-03
  • arXiv 分类: cs.CR, cs.AI
  • 关联标签: agent-security, prompt-injection, memory, arxiv

English Abstract

Modern agentic systems fundamentally reshape the security boundary of LLMs by introducing persistent system state including memories, filesystems, tools, and other long-lived contextual artifacts that survives across sessions. As external information crosses this boundary and becomes part of persistent agent state, malicious instructions are no longer confined to a single interaction, but can silently persist and influence future executions long after the original attacker interaction has ended. We introduce Cross-Session Stored Prompt Injection, a new threat vector inspired by stored cross-site scripting that redefines prompt injection for agentic systems by extending its threat model across both time, where attacks persist and activate across sessions, and space, where adversarial instructions propagate beyond the immediate prompt into persistent system state. To systematically characterize this emerging threat, we formalize the lifecycle of cross-session stored prompt injection, develop a taxonomy of persistence channels and incorporation mechanisms, and build a sandbox toolkit for evaluation. Our findings suggest that the fundamental challenge of agent security is not merely filtering untrusted inputs, but governing how external information acquires authority as it crosses persistent system boundaries. We hope this work motivates a broader shift from interaction-centric security toward state-centric security, making the secure management of persistent agent state a first-class security principle for the agentic era.

English Summary

The paper introduces Cross-Session Stored Prompt Injection: once external information crosses into persistent agent state (memories, filesystems, tools, long-lived contextual artifacts), injected instructions are no longer confined to a single interaction but persist and silently influence future sessions, analogous to stored XSS. The threat model extends prompt injection across both time and space.

Obsidian Notes

  • 内容由 opencli arxiv paper 拉取 arXiv 元数据与摘要生成。
  • 中文导读与价值判断均锚定在条目已有摘要、论文摘要、作者、日期与分类信息上;未补充论文摘要之外的实验细节。