{
  "id": 4174,
  "url": "https://arxiv.org/abs/2605.17634v1",
  "title": "AI Agents May Always Fall for Prompt Injections",
  "summary": "Prompt injection is the most critical vulnerability in deployed AI agents. Despite recent progress, we show that the prevailing defense paradigm (data-instruction separation) both fails to detect attacks that operate through contextual manipulation and degrades contextually appropriate behavior. We then recast prompt injection via the lens of Contextual Integrity (CI), a privacy theory that judges information flow compliance with contextual norms. This explains types of attacks that current defe",
  "authors": "Sahar Abdelnabi, Eugene Bagdasarian",
  "category": "research",
  "topics": "regulation,privacy-surveillance,military-security,agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-05-17T19:55:39.000Z",
  "fetched_at": "2026-07-14T16:30:50.569Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/4174",
  "original_url": "https://arxiv.org/abs/2605.17634v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}