DualView: Defense Against Indirect Prompt Injection in AI Agents

Discover how DualView protects your personal AI agents from indirect prompt injection, even when malicious data is stored and retrieved.

martes, 7 de julio de 2026 • 3 min read • Q2BSTUDIO Team

How DualView blocks stored indirect prompt injection

The rise of artificial intelligence agents operating directly on the user's local computer has represented a qualitative leap in the automation of everyday tasks: from email management to web browsing or file administration. However, this proximity to system resources—network, file system, and shell—opens the door to a growing threat: indirect prompt injection (IPI). Unlike traditional attacks, IPI exploits the agent's trust in data coming from unverified external sources, such as a malicious email or a downloaded document. By reading that data, the agent can interpret it as legitimate commands and execute them without supervision, compromising device security and user privacy.

Initial defenses, based on dual LLM (Large Language Model) models, attempted to isolate untrusted data by replacing it with symbols that the agent could reference but not read. However, these solutions had a critical weakness: they only tracked distrust within the agent's active context. When the agent saved a potentially dangerous piece of data to the file system and later retrieved it, that data—which could contain a malicious instruction—returned to the context as if it were trusted, simply because it had been stored and re-read. This phenomenon, known as stored IPI, demonstrated that any defense ignoring the user's real environment—where humans and programs share the same workspace—is incomplete.

Faced with this challenge, an innovative approach emerges that extends the traceability of untrusted data beyond the agent's context, encompassing the entire user environment: the file system, the shell, the network, and even other agents. The core idea is to provide two different views for each communication channel. In the agent's view, untrusted data is presented as harmless symbols, even after being written and read back, thus blocking stored IPI. Meanwhile, the human view retains the original data so that people and external tools can work with it without restrictions. This dual-view mechanism redirects each tool call to the appropriate environment and synchronizes information between both perspectives, ensuring the agent never comes into direct contact with malicious instructions.

What is interesting about this proposal is that it is deployed as a plugin on top of the existing agent, using only the tool hooks, without needing to modify the agent's internal logic or the implementations of the tools themselves. By isolating untrusted data by design, protection is not limited to known attack patterns but offers an effective barrier against emerging vectors. In evaluations conducted on specific IPI benchmarks and everyday tasks, this solution has been shown to block all injection attempts, including the stored variant, while maintaining utility almost identical to that of an unprotected system.

For companies that are adopting AI for business through local AI agents, security becomes a non-negotiable pillar. Indirect prompt injection can not only expose sensitive data but also allow an attacker to execute arbitrary commands on the system. Therefore, having robust cybersecurity strategies is as important as the agent's functionality itself. At Q2BSTUDIO, we understand that protection must be integrated from the design phase, and that is why we offer artificial intelligence solutions for businesses that prioritize both operational efficiency and data security.

Furthermore, implementing these systems often requires a solid technological ecosystem. Our AWS and Azure cloud services allow deploying agents with the necessary scalability and control, while custom application development and custom software ensure that each tool perfectly adapts to the organization's workflows. Even in the field of data analysis, with business intelligence services like Power BI, we can integrate security alerts that monitor agent behavior in real time.

Ultimately, the evolution of local AI agents is redefining automation, but it also demands rethinking security from a holistic perspective. The dual-view proposal represents a significant advance by closing the stored IPI gap, demonstrating that it is possible to maintain utility without sacrificing protection. For companies looking to make the leap towards intelligent and secure automation, our cybersecurity and pentesting services offer the necessary support to implement these defenses effectively.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.