[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-benchmark-labels-exactly-where-ai-agents-get-hijacked":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},6231,"new-benchmark-labels-exactly-where-ai-agents-get-hijacked","New Benchmark Labels Exactly Where AI Agents Get Hijacked","AgentDrift labels each step of 12,536 AI agent trajectories to show exactly where prompt injections take hold, and simple detectors catch barely half of them.","A new benchmark grades AI agents step by step, and it shows most defenses can't tell when an attack actually works.\n\nResearchers built AgentDrift, a corpus of 12,536 synthetic tool-call trajectories spanning five agent domains, with all 71,024 individual steps labeled benign, injection point, hijacked, or failed injection. The dataset mixes 4,000 clean trajectories with 5,536 successful attacks, 1,500 resisted attacks, and 1,500 hard-negative cases that look suspicious but aren't. A single open-source model generated the trajectories under category-specific rules enforced by a structural validator, and human reviewers hand-audited 1,200 of them - catching cases where even an LLM judge got fooled by the hard negatives.\n\nThe number that should worry anyone building AI agents: a basic logistic-regression detector using surface features caught only 55.4% of attacks overall, and just 8.2% of partial hijacks. That gap matters because it means the difference between an agent that shrugs off a malicious instruction and one that quietly complies is often invisible unless a detector models the full sequence of actions, not just isolated red flags.\n\nMost prompt-injection defenses get graded on whether an attack succeeded, not on where in the trajectory it took hold - which is exactly the blind spot this benchmark was built to expose.","[\"ai-agents\",\"prompt-injection\",\"llm-security\",\"benchmarks\"]","2026-09-10T04:00:00.000Z","2026-09-10T08:22:52.062Z","2026-09-10T08:23:03.980Z","published",null,[],"security",[26,27,28,29],"ai-agents","prompt-injection","llm-security","benchmarks",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.06972",0,{"sections":36},[37,42,45,50,55,60,65,69,74,79,84,89,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3480,"2026-09-11T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",628,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",336,"2026-09-11T00:56:21.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",153,"2026-09-09T15:12:32.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":41},"Science","science",98,{"name":70,"slug":71,"count":72,"latest_published_at":73},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]