@inproceedings{zhan-etal-2025-adaptive, title = "Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on {LLM} Agents", author = "Zhan, Qiusi and Fang, Richard and Panchal, Henil Shalin and Kang, Daniel", editor = "Chiruzzo, Luis and Ritter, Alan and Wang, Lu", booktitle = "Findings of the Association for Computational Linguistics: NAACL 2025", month = apr, year = "2025", address = "Albuquerque, New Mexico", publisher = "Association for Computational Linguistics", url = "https://preview.aclanthology.org/fix-sig-urls/2025.findings-naacl.395/", pages = "7101--7117", ISBN = "979-8-89176-195-7" }