Preliminary research
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Web agents drive a real browser, so untrusted page content reaches the model that decides what to click. MUZZLE red-teams them with an agent rather than fixed templates: it reads the target agent's own trajectories to choose the injection surface and adapt the payload to what the agent does next, where prior evaluations used hand-picked surfaces and so understated the risk.
Record
- Researcher
- Georgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer, William Robertson, Cristina Nita-Rotaru and Alina Oprea
- Published by
- usenix.org
- Topic
- Injection
In the archive
Related sources
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection (Paper) Whitepaper
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks
Tags
This page is the archive's own catalogue record. The research is the work of Georgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer, William Robertson, Cristina Nita-Rotaru and Alina Oprea, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .