ToolTweak: An Attack on Tool Selection in LLM-based Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sneh, Jonathan, Yan, Ruomei, Yu, Jialin, Torr, Philip, Gal, Yarin, Sengupta, Sunando, Sommerlade, Eric, Paren, Alasdair, Bibi, Adel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914072450039808
author Sneh, Jonathan
Yan, Ruomei
Yu, Jialin
Torr, Philip
Gal, Yarin
Sengupta, Sunando
Sommerlade, Eric
Paren, Alasdair
Bibi, Adel
author_facet Sneh, Jonathan
Yan, Ruomei
Yu, Jialin
Torr, Philip
Gal, Yarin
Sengupta, Sunando
Sommerlade, Eric
Paren, Alasdair
Bibi, Adel
contents As LLMs increasingly power agents that interact with external tools, tool use has become an essential mechanism for extending their capabilities. These agents typically select tools from growing databases or marketplaces to solve user tasks, creating implicit competition among tool providers and developers for visibility and usage. In this paper, we show that this selection process harbors a critical vulnerability: by iteratively manipulating tool names and descriptions, adversaries can systematically bias agents toward selecting specific tools, gaining unfair advantage over equally capable alternatives. We present ToolTweak, a lightweight automatic attack that increases selection rates from a baseline of around 20% to as high as 81%, with strong transferability between open-source and closed-source models. Beyond individual tools, we show that such attacks cause distributional shifts in tool usage, revealing risks to fairness, competition, and security in emerging tool ecosystems. To mitigate these risks, we evaluate two defenses: paraphrasing and perplexity filtering, which reduce bias and lead agents to select functionally similar tools more equally. All code will be open-sourced upon acceptance.
format Preprint
id arxiv_https___arxiv_org_abs_2510_02554
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ToolTweak: An Attack on Tool Selection in LLM-based Agents
Sneh, Jonathan
Yan, Ruomei
Yu, Jialin
Torr, Philip
Gal, Yarin
Sengupta, Sunando
Sommerlade, Eric
Paren, Alasdair
Bibi, Adel
Cryptography and Security
Artificial Intelligence
As LLMs increasingly power agents that interact with external tools, tool use has become an essential mechanism for extending their capabilities. These agents typically select tools from growing databases or marketplaces to solve user tasks, creating implicit competition among tool providers and developers for visibility and usage. In this paper, we show that this selection process harbors a critical vulnerability: by iteratively manipulating tool names and descriptions, adversaries can systematically bias agents toward selecting specific tools, gaining unfair advantage over equally capable alternatives. We present ToolTweak, a lightweight automatic attack that increases selection rates from a baseline of around 20% to as high as 81%, with strong transferability between open-source and closed-source models. Beyond individual tools, we show that such attacks cause distributional shifts in tool usage, revealing risks to fairness, competition, and security in emerging tool ecosystems. To mitigate these risks, we evaluate two defenses: paraphrasing and perplexity filtering, which reduce bias and lead agents to select functionally similar tools more equally. All code will be open-sourced upon acceptance.
title ToolTweak: An Attack on Tool Selection in LLM-based Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.02554