AdvSim2Real
AdvSim2Real: Training Web Agents Against Adaptive Prompt Injection in a Web World ModelA training framework co-evolves a task curriculum and an injection adversary inside a web world model to make a web agent more capable and robust against prompt injections.

A web world model co-evolves a task curriculum and an injection adversary to train a web agent. The resulting training data improves the agent's robustness and capability, allowing it to handle more difficult tasks and stronger adversaries in the next iteration.
- Simulator co-evolves tasks and adversaries
- Generates challenging web agent scenarios
- Agent trains on resulting curriculum
- Agent handles harder tasks and attacks
- Simulator co-evolves tasks and adversaries
- Generates challenging web agent scenarios
- Agent trains on resulting curriculum
- Agent handles harder tasks and attacks
Why it is a road to recursion
Co-evolving tasks and adversaries within a world model provides an automated curriculum that continuously pushes the agent's robustness and capabilities without requiring manual task design.
Evidence
Training in the simulator makes a 4B agent both more capable and more robust: its completion rises with and without attacks, holds against a frontier-model adversary it never trained against.
Related loops
More training data →
- Aligned model generates training data
- Reward model judges and filters it
- Data trains next intermediate instruct model
- Next model generates better alignment data
- repeat

- UMM generates images and programs
- Execution verifies programs against specifications
- Verified renders and programs form training data
- Data trains UMM visual and text capabilities
- repeat

- Agent synthesizes agentic pretraining data
- Pipeline adjusts training set in real time
- Data feeds back into model training
- repeat