{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_960a4e289a8d69a692446ff4d6f2b283499e33e95d6d64f69b0e2faa2f1f45cc","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_960a4e289a8d69a692446ff4d6f2b283499e33e95d6d64f69b0e2faa2f1f45cc","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"f838587d2c09b4e3f234524d7de10b0a97aa5ea239c10b216cc859075bccae30","published":"Tue, 16 Jun 2026 00:00:00 -0400","receipt_hash":"f838587d2c09b4e3f234524d7de10b0a97aa5ea239c10b216cc859075bccae30","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"f838587d2c09b4e3f234524d7de10b0a97aa5ea239c10b216cc859075bccae30","observed_at":"2026-06-16T04:43:43.281320Z","parent_run_hash":"eb6edcf82c3507c59161a4ab46d2e904e507004f44677402bb24d106997ed7c2","published":"Tue, 16 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2606.15057v1 Announce Type: cross \nAbstract: Indirect prompt injection (IPI) is a major security threat to LLM-powered agents. Thus, a growing body of work have proposed a variety of defensive approaches against IPI. These can be grouped into three broad categories: 1) prompt-based (using prompting as a way to prevent agents from following malicious instructions), 2) detection-based (identifying and filtering malicious instructions), and 3) system-level (using systems insights, such as control and data isolation, for defense). However, commonly used benchmarks for evaluating defense, such as AgentDojo, are \\emph{inherently static}, generating a fixed distribution of IPI attacks. Consequently, static benchmarks do not usefully evaluate defense robustness to adaptive threats. We address this issue by developing AutoDojo, an adaptive extension of AgentDojo that optimizes IPI against a given defense. Using AutoDojo against state-of-the-art IPI defenses across three task suites and fi","title":"AutoDojo: Adaptive Attacks Expose Superficial Defenses and User-Underspecification Limits in LLM Agents","url":"https://arxiv.org/abs/2606.15057","vendor":"arxiv_cs_ai"},"summary":"arXiv:2606.15057v1 Announce Type: cross \nAbstract: Indirect prompt injection (IPI) is a major security threat to LLM-powered agents. Thus, a growing body of work have proposed a variety of defensive approaches against IPI. These can be grouped into three broad categories: 1) prompt-based (using prompting as a way to prevent agents from following malicious instructions), 2) detection-based (identifying and filtering malicious instructions), and 3) system-level (using systems insights, such as control and data isolation, for defense). However, commonly used benchmarks for evaluating defense, such as AgentDojo, are \\emph{inherently static}, generating a fixed distribution of IPI attacks. Consequently, static benchmarks do not usefully evaluate defense robustness to adaptive threats. We address this issue by developing AutoDojo, an adaptive extension of AgentDojo that optimizes IPI against a given defense. Using AutoDojo against state-of-the-art IPI defenses across three task suites and fi","title":"AutoDojo: Adaptive Attacks Expose Superficial Defenses and User-Underspecification Limits in LLM Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-16T04:43:43Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2606.15057"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:85cc3b224f1f0e58efb3b41f162c5483b78eec845b2187fd16b3b14ae36a29c14f4719454ef16563a94534fc68314d4961c953a8dc04910b0e5710cab9b4e207","signer":"crovia.substrate","subject":{"observed_at":"2026-06-16T04:43:43Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2606.15057"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"16721da9d01ca48de8f113bb0fbc38e199c53ffa224655e0e733c269f28f6d6b","leaf_index":230376,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"01018132ec923c331e22b81e82e67357d17a0bda178b72775c7b7bd8c8171b8b","side":"right"},{"sibling":"c4f241bca409295375a980a001828914b11f28a78455649d377ec00e79ec592f","side":"right"},{"sibling":"85cd0ed006e8c82612e2f65ad477dfed6750b435a7e8accdf70b09bcf00744b8","side":"right"},{"sibling":"46360aa22c19435a62090b6c98f850f3d49e34b9b48e9a0b16ed671a13fc6755","side":"left"},{"sibling":"1dc894ee72d593fab88a90aa044315d906e584c6ae81b062816bae997b0961c3","side":"right"},{"sibling":"e17763328e9d516bfc177e510b9514b6ad5b99940c57243735af35ffccd5e309","side":"left"},{"sibling":"5aa53f259ebf93fa9ac6b1472f46a3e7bcb96175ba6f54b9c2dc9f5fd9ef8711","side":"left"},{"sibling":"a920a6db38b29333b686b08bcb39326c5a67bb5f4588a0647130fe767a058e04","side":"left"},{"sibling":"03ebe4791d56166247160f6ee7788c15745bdd7e274c62ec21b2438669941587","side":"left"},{"sibling":"74897e850164dddc689c3c65b33f9bae0268ab0bf429867a4e193d9b9b685040","side":"left"},{"sibling":"bde25d7e94e64717e426a97f6fcb4907e92b5c61fc89d92d7e0947a2249c3f6b","side":"right"},{"sibling":"d10d772a4984cae00e65ab24af21d1d260e475bbaae3f17871859eb705bd3999","side":"right"},{"sibling":"e79159853f2f35ddae8e3247d515e433c534277b287d65bbd77ae989aa4992fa","side":"right"},{"sibling":"3054319f1840cce0eaaf0bc4b1ae38e5bf8b6210927d924a750775cc7d77cca6","side":"right"},{"sibling":"0fd8b5059f279c4a4a6688de2472fdbc25543fee183df19b21dacca880354cff","side":"right"},{"sibling":"a04392fb9f2a3a620840e3b3fecd93d12e6d224e481c162389d8ae64e7194599","side":"left"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":232015,"merkle_root":"62bfb7809bb55667ad7eeebdb48267b9b2c1ee89bb808ea1e6d3a814a15aa402","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260617T133701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-17T13:39:59Z","sig_algorithm":"ed25519","signature":"930a3563c643cc7518d048b12a1f5392a96a5edce49533ba0a56f11b6cc69319bb1c800aacc46b52a6941c4d05dae255a45cac757d6093c971b96852c24f140e","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_960a4e289a8d69a692446ff4d6f2b283499e33e95d6d64f69b0e2faa2f1f45cc"}}