{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:GFSTCVOALHBEHC2YXIUDHGJDQO","short_pith_number":"pith:GFSTCVOA","schema_version":"1.0","canonical_sha256":"31653155c059c2438b58ba28339923838684cbec207badbfd392b3fd403275eb","source":{"kind":"arxiv","id":"2506.01055","version":1},"attestation_state":"computed","paper":{"title":"Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Daria Stetsenko, Fabrizio Gilardi, Meysam Alizadeh, Zeynab Samei","submitted_at":"2025-06-01T15:48:06Z","abstract_excerpt":"Previous benchmarks on prompt injection in large language models (LLMs) have primarily focused on generic tasks and attacks, offering limited insights into more complex threats like data exfiltration. This paper examines how prompt injection can cause tool-calling agents to leak personal data observed during task execution. Using a fictitious banking agent, we develop data flow-based attacks and integrate them into AgentDojo, a recent benchmark for agentic security. To enhance its scope, we also create a richer synthetic dataset of human-AI banking conversations. In 16 user tasks from AgentDoj"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.01055","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-01T15:48:06Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"f336d0bc202212495c9c365a05f352e690ec281f264138fd61fc274101642763","abstract_canon_sha256":"bf3549d23a45af39999f7583e1649286995ccf7f0b9b99db5c4a00359598232d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:13:45.220836Z","signature_b64":"praAU56SNLXJG583ilxRdMGNe//o+I61v4FsPTz22Hnckf/+pBpgDUmzKIqspS1JFhtLZ+CNh3jgPvJMGkmRAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"31653155c059c2438b58ba28339923838684cbec207badbfd392b3fd403275eb","last_reissued_at":"2026-07-05T11:13:45.220366Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:13:45.220366Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Daria Stetsenko, Fabrizio Gilardi, Meysam Alizadeh, Zeynab Samei","submitted_at":"2025-06-01T15:48:06Z","abstract_excerpt":"Previous benchmarks on prompt injection in large language models (LLMs) have primarily focused on generic tasks and attacks, offering limited insights into more complex threats like data exfiltration. This paper examines how prompt injection can cause tool-calling agents to leak personal data observed during task execution. Using a fictitious banking agent, we develop data flow-based attacks and integrate them into AgentDojo, a recent benchmark for agentic security. To enhance its scope, we also create a richer synthetic dataset of human-AI banking conversations. In 16 user tasks from AgentDoj"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.01055","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.01055/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.01055","created_at":"2026-07-05T11:13:45.220422+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.01055v1","created_at":"2026-07-05T11:13:45.220422+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.01055","created_at":"2026-07-05T11:13:45.220422+00:00"},{"alias_kind":"pith_short_12","alias_value":"GFSTCVOALHBE","created_at":"2026-07-05T11:13:45.220422+00:00"},{"alias_kind":"pith_short_16","alias_value":"GFSTCVOALHBEHC2Y","created_at":"2026-07-05T11:13:45.220422+00:00"},{"alias_kind":"pith_short_8","alias_value":"GFSTCVOA","created_at":"2026-07-05T11:13:45.220422+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":13,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2606.23277","citing_title":"GIF: Locally Sound Geometric Information Flow Control for LLMs","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2606.18996","citing_title":"TRAP: Benchmark for Task-completion and Resistance to Active Privacy-extraction","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2606.13385","citing_title":"Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12666","citing_title":"CAPED: Context-Aware Privacy Exposure Defense for Mobile GUI Agents","ref_index":37,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02302","citing_title":"SeClaw: Spec-Driven Security Task Synthesis for Evaluating Autonomous Agents","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23989","citing_title":"Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security","ref_index":193,"is_internal_anchor":false},{"citing_arxiv_id":"2605.25435","citing_title":"Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30650","citing_title":"When AI Meets Wall Street: A Survey on Trustworthy AI in Fintech","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18133","citing_title":"An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2601.18842","citing_title":"GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2604.01473","citing_title":"SelfGrader: LLM Jailbreak Detection via Anchored Token-Level Logits","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06393","citing_title":"Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation","ref_index":31,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO","json":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO.json","graph_json":"https://pith.science/api/pith-number/GFSTCVOALHBEHC2YXIUDHGJDQO/graph.json","events_json":"https://pith.science/api/pith-number/GFSTCVOALHBEHC2YXIUDHGJDQO/events.json","paper":"https://pith.science/paper/GFSTCVOA"},"agent_actions":{"view_html":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO","download_json":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO.json","view_paper":"https://pith.science/paper/GFSTCVOA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.01055&json=true","fetch_graph":"https://pith.science/api/pith-number/GFSTCVOALHBEHC2YXIUDHGJDQO/graph.json","fetch_events":"https://pith.science/api/pith-number/GFSTCVOALHBEHC2YXIUDHGJDQO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO/action/storage_attestation","attest_author":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO/action/author_attestation","sign_citation":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO/action/citation_signature","submit_replication":"https://pith.science/pith/GFSTCVOALHBEHC2YXIUDHGJDQO/action/replication_record"}},"created_at":"2026-07-05T11:13:45.220422+00:00","updated_at":"2026-07-05T11:13:45.220422+00:00"}