全部文章0

Hacker Newszhinit··访问 1

Prismata: Confining cross-site prompt injection in web agents

原网页

Computer Science > Cryptography and Security

arXiv:2607.08147 (cs) [Submitted on 9 Jul 2026]

Title:Prismata: Confining Cross-Site Prompt Injection in Web Agents

Authors:Corban Villa, Alp Eren Ozdarendeli, Sijun Tan, Raluca Ada Popa View a PDF of the paper titled Prismata: Confining Cross-Site Prompt Injection in Web Agents, by Corban Villa and 2 other authors View PDF HTML (experimental)
Abstract:Autonomous web agents promise to automate everyday browsing tasks, but inherit one of the web's oldest attack surfaces. Cross-Site Scripting proved that mixing trusted and untrusted content is dangerous, even on benign pages. Agents resurface this risk by interpreting natural language as instructions, allowing third-party and user-generated content to hijack the agent via prompt injection. The core challenge is that deriving a task-specific security policy requires reasoning over page structure that is entangled with the attacker's content.
We present Prismata, a defense enforcing contextual least privilege for web agents, constraining both what the agent sees and what it can do. Prismata's dynamic trust derivation produces permission labels for page content, with structural confinement guarantees, inspired by classical integrity models, that bound any labeling errors so that labels can only decrease in privilege and mislabelings are bounded. Prismata's mechanical confinement enforces these labels by redacting content and restricting agent capabilities. Importantly, these mechanisms require no developer annotations, so Prismata supports the long tail of websites. Across recent published web agent attacks, including adaptive variants, Prismata substantially reduces attack success while preserving benign task utility.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2607.08147 [cs.CR]
  (or arXiv:2607.08147v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2607.08147 arXiv-issued DOI via DataCite

Submission history

From: Corban Villa [view email]
[v1] Thu, 9 Jul 2026 06:37:52 UTC (4,724 KB)
Full-text links:

Access Paper:

license icon view license

Current browse context:

cs.CR < prev   |   next >
new | recent | 2026-07 Change to browse by: cs
cs.AI

References & Citations

Loading...

BibTeX formatted citation

Data provided by:

Bookmark

BibSonomy Reddit Bibliographic Tools

Bibliographic and Citation Tools

Bibliographic Explorer Toggle Bibliographic Explorer (What is the Explorer?) Connected Papers Toggle Connected Papers (What is Connected Papers?) Litmaps Toggle Litmaps (What is Litmaps?) scite.ai Toggle scite Smart Citations (What are Smart Citations?) Code, Data, Media

Code, Data and Media Associated with this Article

alphaXiv Toggle alphaXiv (What is alphaXiv?) Links to Code Toggle CatalyzeX Code Finder for Papers (What is CatalyzeX?) DagsHub Toggle DagsHub (What is DagsHub?) GotitPub Toggle Gotit.pub (What is GotitPub?) Huggingface Toggle Hugging Face (What is Huggingface?) ScienceCast Toggle ScienceCast (What is ScienceCast?) Demos

Demos

Replicate Toggle Replicate (What is Replicate?) Spaces Toggle Hugging Face Spaces (What is Spaces?) Spaces Toggle TXYZ.AI (What is TXYZ.AI?) Related Papers

Recommenders and Search Tools

Link to Influence Flower Influence Flower (What are Influence Flowers?) Core recommender toggle CORE Recommender (What is CORE?) About arXivLabs

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)