AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI Frameworks

arXiv · AI, language, vision and robotics · article · Sep 8, 2026 · UTC

Agentic AI frameworks let a language model plan, keep memory, and call tools that reach real files, mail, and services. Most of these agents also read images, which gives an attacker a way to put text into the agent's context without going through the user. We present MMPIBench, a reproducible benchmark that measures what happens next. It delivers a fixed set of attacks through six visual carriers (OCR text, overlays, EXIF metadata, QR codes, fake interfaces, and hybrids) and records how far each injected instruction travels through the agent, from perception through planning to the tool call.

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-20T19:52:05.078Z. This is not the publication date.