Rethinking Indirect Prompt Injection as a Test-Time Search Problem
This paper proposes redefining indirect hints as searching for problems during tests conducted on task-related attacks induced by the environment, user tasks, and injection tasks. To this end, researchers introduce a proxy attacker equipped with a dedicated search framework that performs environmental reconnaissance, structured reasoning regarding attack strategies, and uses victim proxy feedback for adaptive evaluation. Experiments across heterogeneous tasks show that increasing the test-time computational effort of the attacker can improve vulnerability detection and utilization efficiency; ablation experiments confirm that explicit strategy management is crucial for avoiding redundant searches and maintaining benefits with a larger budget. These results suggest that proxy security evaluation should characterize both the attacker’s search process and computational budget, rather than viewing attack success as an independent attribute of the victim. Additionally, the study indicates that the attacker’s adaptive search on the system attack surface is an important and underexplored security risk for tool-use proxies.