Alphabell.
Paper · Training data

AdvSim2Real

AdvSim2Real: Training Web Agents Against Adaptive Prompt Injection in a Web World ModelA training framework co-evolves a task curriculum and an injection adversary inside a web world model to make a web agent more capable and robust against prompt injections.

AdvSim2Real
Figure from the paper, arXiv. Source
The loop

A web world model co-evolves a task curriculum and an injection adversary to train a web agent. The resulting training data improves the agent's robustness and capability, allowing it to handle more difficult tasks and stronger adversaries in the next iteration.

The loop
AdvSim2Real
Paper · arXiv
  1. Simulator co-evolves tasks and adversaries
  2. Generates challenging web agent scenarios
  3. Agent trains on resulting curriculum
  4. Agent handles harder tasks and attacks
  1. Simulator co-evolves tasks and adversaries
  2. Generates challenging web agent scenarios
  3. Agent trains on resulting curriculum
  4. Agent handles harder tasks and attacks
↻ The improved system does the next round, and the loop turns again.

Why it is a road to recursion

Co-evolving tasks and adversaries within a world model provides an automated curriculum that continuously pushes the agent's robustness and capabilities without requiring manual task design.

Evidence

Training in the simulator makes a 4B agent both more capable and more robust: its completion rises with and without attacks, holds against a frontier-model adversary it never trained against.

web-agentsadversarial-trainingprompt-injection