Adaptive simulated training makes web agents more resistant to prompt injection

Co-evolving tasks and attacks improved a 4-billion-parameter agent’s completion rates in simulation, including against an unseen adversary.

Big Tech
Sarim Hashmi · Mukul Ranjan · Kshitij Mishra · Mikhail Kuznetsov · Praneeth Vepakomma · Nils Lukas

Mohamed bin Zayed University of Artificial Intelligence · Amazon · Massachusetts Institute of Technology

Research Digest··2 min read
Hashmi et al.

The authors developed AdvSim2Real, a two-stage training framework built around WebWorld-14B, a frozen model that predicts how webpages change after an agent acts.

Why this paper

From Amazon and 2 others

In one line

AdvSim2Real co-evolves tasks, attacks, and a web agent in a simulated world, raising task completion under unseen attacks by 33.6%.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ✓Compute or model size stated (params 4B)
  • ✓Limitations stated by the authors (3 noted)
  • ✓Reports numbers on named benchmarks

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.