Beyond Prompt Injection: When AI Agents Mistake Content for Trusted Data
A new LLM security paper from Prof Luyi Xing's group shows how an attacker can distort an AI agent's view of the world by leaving carefully formatted content in a product review, GitHub comment, email, or chat message, w…