A Self-Improving Red-Teamer Takes Claude Opus 4.8 From 4% to 24% Injection Success on Computer-Use Tasks
SIR is a black-box indirect prompt injection attack against computer-use agents at the operating-system level, composing stealthy injections from a small plain-language library of reusable principles and then diagnosing failed trajectories to distill new named strategies that get reapplied. Scored with a deterministic oracle checking filesystem, service and permission state rather than an LLM judge, it lifts attack success from 4% to 24% on Claude Opus 4.8 and from 0% to 28% on Gemini 3.5 Flash while the benign task still completes. Principles discovered against one model transfer to a different architecture with no additional feedback, so fixed hand-written injection benchmarks understate real exposure.
↳ Follow the thread