---
格式版本: 2
标题: "Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection"
原文链接: "https://arxiv.org/abs/2608.16393"
发布日期: "2026-08-17"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:scrape:strict_html_body"
发布时间证据: "citation_date: 2026/08/17"
发布时间校准原因: "规则确认唯一严格发布时间，来源 scrape:strict_html_body"
发布时间校准置信度: "high"
发布时间候选数量: 6
发布时间严格候选数量: 6
发布时间原页读取状态: ""
发布时间未找到原因: ""
发布时间校准时间: "2026-08-18T19:35:35+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-18T19:35:26+08:00"
入库时间: "2026-08-18T11:35:43.253Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为DeepSeek Harness的提示注入安全评估，属于AI安全领域，与超节点/AI Rack/机柜级AI基础设施、供电、散热、互连等完全无关。"
AI质检模型: "tx-deepseek-v4-flash"
AI质检时间: "2026-08-18T19:36:43+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 3
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "研究人员使用AI-Infra-Guard对DeepSeek Harness进行间接提示注入安全评估。在14,560次受控执行中，最高攻击成功率达25.5%（文件模式的隐藏Unicode攻击），并公开了评测代码。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:25:40.264Z"
采集批次: "2026年8月18日15点52分05秒"
采集批次ID: "20260818-155205-090"
去重键: "https://arxiv.org/abs/2608.16393"
---

## Computer Science > Cryptography and Security

## Title:Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection

Authors:[Zonghao Ying](https://arxiv.org/search/cs?searchtype=author&query=Ying,+Z), [Xiangfan Wu](https://arxiv.org/search/cs?searchtype=author&query=Wu,+X), [Huiyu Wu](https://arxiv.org/search/cs?searchtype=author&query=Wu,+H), [Xing Zheng](https://arxiv.org/search/cs?searchtype=author&query=Zheng,+X), [Huangsheng Cheng](https://arxiv.org/search/cs?searchtype=author&query=Cheng,+H), [Xiaorong Shi](https://arxiv.org/search/cs?searchtype=author&query=Shi,+X), [Jing Guo](https://arxiv.org/search/cs?searchtype=author&query=Guo,+J)

[View PDF](https://arxiv.org/pdf/2608.16393) [HTML (experimental)](https://arxiv.org/html/2608.16393v1)

> Abstract:We assess indirect prompt injection in DeepSeek Harness (DSH), using AI-Infra-Guard (A.I.G) to construct tests, deliver controlled taint, execute DSH, collect traces, and judge outcomes. The study covers 14,560 controlled executions over 16 indirect-content channels, text and file carrier modes, 35 payload objectives, one unmodified baseline, and 12 attack methods. The experiment preserves DSH's agent loop, tool registry, model adapter, and session-event path; source tools and sensitive sinks are local fixtures, so attempted actions are recorded without external side effects. We evaluate each trace with a deterministic rule-based judge, \\JudgeR{} (RuleJudge), and a semantic LLM-based judge, \\JudgeL{} (LLMJudge). The strongest observed attack success rates are 17.0% under \\JudgeL{} for fake-completion attack in text mode, 25.5% under \\JudgeR{} for hidden Unicode in file mode, and 16.0% under \\JudgeR{} for the skills channel in file mode. \\JudgeL{} also assigns partial compliance more often than \\JudgeR{} (7.3% versus 2.0%). We relate these results to DSH's treatment of tool results, additional contexts, and tool-call policy hooks, then identify controls that should sit between untrusted content and sensitive actions. Our code is available at [this https URL](https://github.com/Tencent/AI-Infra-Guard).

| Subjects: | Cryptography and Security (cs.CR) |
| --- | --- |
| Cite as: | [arXiv:2608.16393](https://arxiv.org/abs/2608.16393) \[cs.CR\] |
|  | (or [arXiv:2608.16393v1](https://arxiv.org/abs/2608.16393v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.16393](https://doi.org/10.48550/arXiv.2608.16393) |

## Submission history

From: Zonghao Ying \[[view email](https://arxiv.org/show-email/2843d817/2608.16393)\]  
**\[v1\]** Mon, 17 Aug 2026 10:43:07 UTC (4,924 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.16393) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
