PulseAugur
实时 06:31:33
English(EN) Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning

新基准揭示用户提示如何影响 AI 编码代理的易感性

一个名为 CIPR 的新基准已被开发出来,用于评估编码代理对存储库投毒的易感性。该基准系统地改变了被投毒的真实存储库中的用户定义的“提示级别配置”(PLCs)。研究发现,任务类型显著影响攻击成功率,其中测试执行任务呈现出特别隐蔽的攻击面。此外,提示的表达方式会间接改变风险,不明确的提示可能会通过限制执行深度来降低攻击成功率,而嘈杂的提示有时会抑制警报。 AI

影响 强调了用户交互模式如何被利用来损害 AI 编码代理,强调了安全提示工程实践的必要性。

排序理由 学术论文,介绍了一个新的基准和关于 AI 代理安全性的发现。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.CL 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新基准揭示用户提示如何影响 AI 编码代理的易感性

本文如何被排名

Signal score
30 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
学术论文,介绍了一个新的基准和关于 AI 代理安全性的发现。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
paper, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. arXiv cs.CL TIER_1 English(EN) · Fukang Zhu, Binbin Zhao, Ruixiao Lin, Ping He, Tianyu Du, Shouling Ji ·

    超越载荷:用户调用如何塑造编码代理对存储库投毒的易感性

    arXiv:2608.30686v1 Announce Type: cross Abstract: Coding agents are increasingly used for software engineering tasks, including bootstrapping projects from third-party repositories whose integrity cannot be assumed. Prior work on repository poisoning largely focuses on attacker-c…