{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:HDPJYVBPXYCBUOTCXGI3UKEELC","short_pith_number":"pith:HDPJYVBP","schema_version":"1.0","canonical_sha256":"38de9c542fbe041a3a62b991ba288458adc2118fce88569a42e13a1f55dff5ff","source":{"kind":"arxiv","id":"2605.24659","version":1},"attestation_state":"computed","paper":{"title":"IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Jiaxiang Chen, Ke Xu, Li Luo, Tanfeng Sun, Xiaoxiang Huang, Xinghao Jiang, Zixuan Chen","submitted_at":"2026-05-23T17:00:06Z","abstract_excerpt":"LLM-based agents are increasingly deployed for complex tasks requiring planning, tool use, and interaction with external services. Their reliance on untrusted external content exposes them to indirect prompt injection (IPI), in which adversarial instructions embedded in retrieved data hijack agent behavior. Existing attacks rely on static payloads that cannot adapt to agent-specific defenses; even recent adaptive methods lack structured feedback to guide optimization. We introduce \\oursys, a feedback-guided iterative framework that closes the loop between injection, diagnosis, and refinement: "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.24659","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-23T17:00:06Z","cross_cats_sorted":[],"title_canon_sha256":"9c78ac7bf76c27a440acc31f87783bacea75766345e58c46b683c205dff2ff62","abstract_canon_sha256":"42beaf75b1aa4f5bd5004dcaf9853e9f1db3b6d36c831f5c3a8279437f8f9b17"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:03:51.732249Z","signature_b64":"NIVsmMvTxP92MWj2r+Jpj6X+i2Cms/zqTSOXSOaIY24GnfWBeE3jhQTiJQ3ePCaG5w4edVuPQaw1Fjfpoj98BQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"38de9c542fbe041a3a62b991ba288458adc2118fce88569a42e13a1f55dff5ff","last_reissued_at":"2026-05-26T01:03:51.731258Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:03:51.731258Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Jiaxiang Chen, Ke Xu, Li Luo, Tanfeng Sun, Xiaoxiang Huang, Xinghao Jiang, Zixuan Chen","submitted_at":"2026-05-23T17:00:06Z","abstract_excerpt":"LLM-based agents are increasingly deployed for complex tasks requiring planning, tool use, and interaction with external services. Their reliance on untrusted external content exposes them to indirect prompt injection (IPI), in which adversarial instructions embedded in retrieved data hijack agent behavior. Existing attacks rely on static payloads that cannot adapt to agent-specific defenses; even recent adaptive methods lack structured feedback to guide optimization. We introduce \\oursys, a feedback-guided iterative framework that closes the loop between injection, diagnosis, and refinement: "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24659","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.24659/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.24659","created_at":"2026-05-26T01:03:51.731445+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.24659v1","created_at":"2026-05-26T01:03:51.731445+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24659","created_at":"2026-05-26T01:03:51.731445+00:00"},{"alias_kind":"pith_short_12","alias_value":"HDPJYVBPXYCB","created_at":"2026-05-26T01:03:51.731445+00:00"},{"alias_kind":"pith_short_16","alias_value":"HDPJYVBPXYCBUOTC","created_at":"2026-05-26T01:03:51.731445+00:00"},{"alias_kind":"pith_short_8","alias_value":"HDPJYVBP","created_at":"2026-05-26T01:03:51.731445+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC","json":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC.json","graph_json":"https://pith.science/api/pith-number/HDPJYVBPXYCBUOTCXGI3UKEELC/graph.json","events_json":"https://pith.science/api/pith-number/HDPJYVBPXYCBUOTCXGI3UKEELC/events.json","paper":"https://pith.science/paper/HDPJYVBP"},"agent_actions":{"view_html":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC","download_json":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC.json","view_paper":"https://pith.science/paper/HDPJYVBP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.24659&json=true","fetch_graph":"https://pith.science/api/pith-number/HDPJYVBPXYCBUOTCXGI3UKEELC/graph.json","fetch_events":"https://pith.science/api/pith-number/HDPJYVBPXYCBUOTCXGI3UKEELC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC/action/storage_attestation","attest_author":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC/action/author_attestation","sign_citation":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC/action/citation_signature","submit_replication":"https://pith.science/pith/HDPJYVBPXYCBUOTCXGI3UKEELC/action/replication_record"}},"created_at":"2026-05-26T01:03:51.731445+00:00","updated_at":"2026-05-26T01:03:51.731445+00:00"}