Preprint
Aug 2026
StepJack: Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection
This paper introduces multi-step indirect prompt injection, a new attack class against CUAs in which the adversarial goal is decomposed into multiple innocuous-looking sub-steps and distributed across a chain of pages referenced along the agent's navigation path.
Zhuoxin Zhan, Akbar Rafiey, A. Ma et al.
· 1 citation