AuraTracer智迹闻
中文

EVENT DOSSIER

Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection

2026-09-07 12:00 Models 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
3mentions
SummaryAI generated

The researchers proposed Repeat-After-Me, a black-box adaptive visual prompt injection attack that requires no semantic correlation with the target model or oral authorization. Experiments showed that the attack’s success rate on visual language models such as Qwen3.6-27B and GPT-5.5 exceeded 80% and 47%, respectively. Even after optimizing the single agent model, the attack still maintained a 43%-46% original success rate for both commercial victims, with cross-sample transferability remaining at 64%-66%. The researchers verified the effectiveness of the attack in the OpenClaw real environment, indicating that untrusted users could enable sensitive behaviors such as remote code execution and secret leakage by minimizing the size of the injected images to cover TOOLS.md. This attack vector remains effective even when adaptive text prompt injection fails.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
GPT-5.5OpenClawQwen3.6-27B

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
GPT-5.5 × OpenClaw1GPT-5.5 × Qwen3.6-27B1OpenClaw × Qwen3.6-27B1

SignalsSIGNALS

Keyword heat
  • Qwen3.6-27B1
  • GPT-5.51
  • OpenClaw1

All reports (1)SOURCES

A arXiv cs.AI en 2026-09-07 12:00

Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection

研究人员提出 Repeat-After-Me,这是一种黑盒自适应视觉提示注入攻击方法。该方法可在 Qwen3.6-27B 和 GPT-5.5 等开源及商业前沿视觉语言模型上实现超过 80% 和 47% 的攻击成功率(ASR),且无需目标提示语义相关或口头授权。实验显示,在单一代理模型优化的注入对两个商业受害者保留 43%-46% 的原始 ASR,跨样本可转移性保留 64%-66%。研究者在 OpenClaw 真实环境中验证了攻击效果:未信任用户可通过最小化注入图像覆盖 TOOLS.md,从而启用远程代码执行和秘密外泄等敏感行为。该攻击向量在自适应文本提示注入失效的场景中依然有效。