Hacker News · Prompt Injection· zhinit·· 2026/07/11AI 评分44
Prismata:约束网页智能体中的跨站提示词注入
原文标题:Prismata: Confining cross-site prompt injection in web agents
AI 导读
Prismata 是一种针对网页智能体的防御方案,通过上下文最小权限同时约束智能体可见内容与可执行操作。其动态信任推导为页面内容生成权限标签,并借鉴经典完整性模型提供结构化约束保证,使标签权限只能降低、误标范围有界;机械约束则通过内容脱敏和能力限制执行这些标签,且无需开发者标注。在近期已发表的网页智能体攻击(含自适应变体)上,Prismata 大幅降低攻击成功率,同时保持正常任务效用。
正文
当前语言的正文正在等待翻译,暂时显示原文。
Abstract:Autonomous web agents promise to automate everyday browsing tasks, but inherit one of the web's oldest attack surfaces. Cross-Site Scripting proved that mixing trusted and untrusted content is dangerous, even on benign pages. Agents resurface this risk by interpreting natural language as instructions, allowing third-party and user-generated content to hijack the agent via prompt injection. The core challenge is that deriving a task-specific security policy requires reasoning over page structure that is entangled with the attacker's content.
We present Prismata, a defense enforcing contextual least privilege for web agents, constraining both what the agent sees and what it can do. Prismata's dynamic trust derivation produces permission labels for page content, with structural confinement guarantees, inspired by classical integrity models, that bound any labeling errors so that labels can only decrease in privilege and mislabelings are bounded. Prismata's mechanical confinement enforces these labels by redacting content and restricting agent capabilities. Importantly, these mechanisms require no developer annotations, so Prismata supports the long tail of websites. Across recent published web agent attacks, including adaptive variants, Prismata substantially reduces attack success while preserving benign task utility.
来源:Hacker News · Prompt Injection · arxiv.org