MbrlCatalogueTitleDetail

Do you wish to reserve the book?
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
Hey, we have placed the reservation for you!
Hey, we have placed the reservation for you!
By the way, why not check out events that you can attend while you pick your title.
You are currently in the queue to collect this book. You will be notified once it is your turn to collect the book.
Oops! Something went wrong.
Oops! Something went wrong.
Looks like we were not able to place the reservation. Kindly try again later.
Are you sure you want to remove the book from the shelf?
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
Oops! Something went wrong.
Oops! Something went wrong.
While trying to remove the title from your shelf something went wrong :( Kindly try again later!
Title added to your shelf!
Title added to your shelf!
View what I already have on My Shelf.
Oops! Something went wrong.
Oops! Something went wrong.
While trying to add the title to your shelf something went wrong :( Kindly try again later!
Do you wish to request the book?
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

Please be aware that the book you have requested cannot be checked out. If you would like to checkout this book, you can reserve another copy
How would you like to get it?
We have requested the book for you! Sorry the robot delivery is not available at the moment
We have requested the book for you!
We have requested the book for you!
Your request is successful and it will be processed during the Library working hours. Please check the status of your request in My Requests.
Oops! Something went wrong.
Oops! Something went wrong.
Looks like we were not able to place your request. Kindly try again later.
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
Paper

XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants

2026
Request Book From Autostore and Choose the Collection Method
Overview
AI coding assistants are widely used for tasks like code generation. These tools now require large and complex contexts, automatically sourced from various origins\\(x2014\\)across files, projects, and contributors\\(x2014\\)forming part of the prompt fed to underlying LLMs. This automatic context-gathering introduces new vulnerabilities, allowing attackers to subtly poison input to compromise the assistant's outputs, potentially generating vulnerable code or introducing critical errors. We propose a novel attack, Cross-Origin Context Poisoning (XOXO), that is challenging to detect as it relies on adversarial code modifications that are semantically equivalent. Traditional program analysis techniques struggle to identify these perturbations since the semantics of the code remains correct, making it appear legitimate. This allows attackers to manipulate coding assistants into producing incorrect outputs, while shifting the blame to the victim developer. We introduce a novel, task-agnostic, black-box attack algorithm GCGS that systematically searches the transformation space using a Cayley Graph, achieving a 75.72% attack success rate on average across five tasks and eleven models, including GPT 4.1 and Claude 3.5 Sonnet v2 used by popular AI coding assistants. Furthermore, defenses like adversarial fine-tuning are ineffective against our attack, underscoring the need for new security measures in LLM-powered coding tools.
Publisher
Cornell University Library, arXiv.org