AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

AgentDrift: A Step-Labeled Benchmark of Injection-Hijacked LLM Agent Trajectories

arXiv · AI, language, vision and robotics · article · Sep 7, 2026 · UTC

LLM agents complete tasks by issuing sequences of tool calls, and every observation they read is a channel through which an indirect prompt injection can enter. A successful injection has a characteristic shape when the trajectory is read in order: a benign prefix gives way to actions that serve the attacker rather than the user. Existing benchmarks measure whether such attacks succeed against live agents, and existing guard models judge a trace as a whole; no public corpus labels, step by step, where an injection enters a trajectory and which steps it corrupts. We present AgentDrift, a benchm

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-20T20:52:10.320Z. This is not the publication date.