| Task Name | Dataset Name | SOTA Result | Trend | |
|---|---|---|---|---|
| Targeted Attack | InjecAgent | ASR@348 | 55 | |
| Trojan Attack | InjecAgent | ASR49 | 36 | |
| Attack Success Rate | InjecAgent | Attack Success Rate (ASR)88.3 | 32 | |
| Prompt Injection Attack | InjecAgent | ASR @ 1 Attempt0 | 32 | |
| Tool Attack Defense | InjecAgent random topology (test) | ASR@10.375 | 16 | |
| Agent behavioral safety | InjecAgent | Safety Rate95.1 | 14 | |
| Indirect Prompt Injection | InjecAgent | Base ASR0.3 | 12 | |
| RAG Poisoning Defense | Extended InjecAgent RAG Poisoning | ASR0 | 12 | |
| Prompt Injection Defense | InjecAgent | ASR0 | 9 | |
| App Data Stealing Defense | Extended InjecAgent App Data Stealing | ASR0 | 9 | |
| App Compromise Defense | Extended InjecAgent App Compromise | ASR0 | 9 | |
| Tool Attack Defense | InjecAgent random architecture | ASR7.3 | 6 | |
| Tool-agent security evaluation | InjecAgent | ASR0 | 6 | |
| Indirect Prompt Injection Defense | InjecAgent external stress (test) | DH Block Rate100 | 4 | |
| Security Evaluation | InjecAgent | Direct Harm86.08 | 4 | |
| Propagation Detection | InjecAgent enhanced | Precision1 | 2 | |
| Propagation Detection | InjecAgent base | Precision100 | 2 | |
| Indirect injection interception | InjecAgent all malicious 100 samples | Interception Rate (IR)100 | 2 | |
| Attack Detection | InjecAgent Agentic Attacks | Detection Rate0.99 | 2 |