AdvSim2Real trains web agents against adaptive prompt injection
The AdvSim2Real paper presents a simulated training setup that co-evolves web tasks, adaptive prompt-injection attacks, and an agent in a frozen web world model. The authors report that training a 4B agent this way improved completion with and without attacks, transferred to a real browser, and increased completion under an unseen frontier-model adversary by 33.6% relative to the base agent on 150 web tasks.