AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

CoER: Defending against Adaptive Indirect Prompt Injection via Adversarial Co-Evolution and Refinement

arXiv · AI, language, vision and robotics · article · Sep 7, 2026 · UTC

Language-model agents are vulnerable to indirect prompt injection (IPI) during tool use: adversarial instructions hidden in untrusted tool outputs can covertly redirect legitimate task execution. Existing work often trains and evaluates defenses against fixed attacks that do not adapt to the defender's behavior, so the resulting defenses may struggle against adaptive attacks. We combine adaptive attacker-defender co-training with subsequent refinement: continued interaction improves both roles, while learned attackers provide training challenges for further gains in defender safety and task ut

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-20T20:32:20.942Z. This is not the publication date.