ToolTweak: An Attack on Tool Selection in LLM-based Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Sneh, Jonathan, Yan, Ruomei, Yu, Jialin, Torr, Philip, Gal, Yarin, Sengupta, Sunando, Sommerlade, Eric, Paren, Alasdair, Bibi, Adel |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MIP against Agent: Malicious Image Patches Hijacking Multimodal OS Agents
by: Aichberger, Lukas, et al.
Published: (2025)
by: Aichberger, Lukas, et al.
Published: (2025)
BiasBusters: Uncovering and Mitigating Tool Selection Bias in Large Language Models
by: Blankenstein, Thierry, et al.
Published: (2025)
by: Blankenstein, Thierry, et al.
Published: (2025)
Prompt Injection Attack to Tool Selection in LLM Agents
by: Shi, Jiawen, et al.
Published: (2025)
by: Shi, Jiawen, et al.
Published: (2025)
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026)
by: Hu, Yuepeng, et al.
Published: (2026)
Shh, don't say that! Domain Certification in LLMs
by: Emde, Cornelius, et al.
Published: (2025)
by: Emde, Cornelius, et al.
Published: (2025)
OMNI-LEAK: Orchestrator Multi-Agent Network Induced Data Leakage
by: Naik, Akshat, et al.
Published: (2026)
by: Naik, Akshat, et al.
Published: (2026)
Select Me! When You Need a Tool: A Black-box Text Attack on Tool Selection
by: Chen, Liuji, et al.
Published: (2025)
by: Chen, Liuji, et al.
Published: (2025)
Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM Agents
by: Li, Zichuan, et al.
Published: (2025)
by: Li, Zichuan, et al.
Published: (2025)
Imprompter: Tricking LLM Agents into Improper Tool Use
by: Fu, Xiaohan, et al.
Published: (2024)
by: Fu, Xiaohan, et al.
Published: (2024)
Security Attacks on LLM-based Code Completion Tools
by: Cheng, Wen, et al.
Published: (2024)
by: Cheng, Wen, et al.
Published: (2024)
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback
by: Yan, Lecheng, et al.
Published: (2026)
by: Yan, Lecheng, et al.
Published: (2026)
Memory-Induced Tool-Drift in LLM Agents
by: Dabas, Mahavir, et al.
Published: (2026)
by: Dabas, Mahavir, et al.
Published: (2026)
AgentGuard: An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
by: Luo, Jiaqi, et al.
Published: (2026)
by: Luo, Jiaqi, et al.
Published: (2026)
Fundamental Limitations in Pointwise Defences of LLM Finetuning APIs
by: Davies, Xander, et al.
Published: (2025)
by: Davies, Xander, et al.
Published: (2025)
The Verifier Tax: Horizon Dependent Safety Success Tradeoffs in Tool Using LLM Agents
by: Sah, Tanmay, et al.
Published: (2026)
by: Sah, Tanmay, et al.
Published: (2026)
SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy
by: Dehghantanha, Ali, et al.
Published: (2026)
by: Dehghantanha, Ali, et al.
Published: (2026)
AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents
by: Rassul, Yassin H., et al.
Published: (2026)
by: Rassul, Yassin H., et al.
Published: (2026)
The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents
by: Wu, Baoyuan, et al.
Published: (2026)
by: Wu, Baoyuan, et al.
Published: (2026)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
by: He, Yu, et al.
Published: (2026)
by: He, Yu, et al.
Published: (2026)
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
by: Wang, Che, et al.
Published: (2026)
by: Wang, Che, et al.
Published: (2026)
Semantic Denial of Service in LLM-controlled robots
by: Steinberg, Jonathan, et al.
Published: (2026)
by: Steinberg, Jonathan, et al.
Published: (2026)
Causality Laundering: Denial-Feedback Leakage in Tool-Calling LLM Agents
by: Chinaei, Mohammad Hossein
Published: (2026)
by: Chinaei, Mohammad Hossein
Published: (2026)
Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools
by: Hawkes, Sophie, et al.
Published: (2024)
by: Hawkes, Sophie, et al.
Published: (2024)
Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System
by: Jiang, Ziyou, et al.
Published: (2025)
by: Jiang, Ziyou, et al.
Published: (2025)
OpenClaw PRISM: A Zero-Fork, Defense-in-Depth Runtime Security Layer for Tool-Augmented LLM Agents
by: Li, Frank
Published: (2026)
by: Li, Frank
Published: (2026)
Quantitative Certification of Agentic Tool Selection
by: Yeon, Jehyeok, et al.
Published: (2025)
by: Yeon, Jehyeok, et al.
Published: (2025)
API Security Based on Automatic OpenAPI Mapping
by: Levi, Yarin, et al.
Published: (2026)
by: Levi, Yarin, et al.
Published: (2026)
Model Tampering Attacks Enable More Rigorous Evaluations of LLM Capabilities
by: Che, Zora, et al.
Published: (2025)
by: Che, Zora, et al.
Published: (2025)
Defensible Design for OpenClaw: Securing Autonomous Tool-Invoking Agents
by: Li, Zongwei, et al.
Published: (2026)
by: Li, Zongwei, et al.
Published: (2026)
Reasoning Introduces New Poisoning Attacks Yet Makes Them More Complicated
by: Foerster, Hanna, et al.
Published: (2025)
by: Foerster, Hanna, et al.
Published: (2025)
HarnessAgent: Scaling Automatic Fuzzing Harness Construction with Tool-Augmented LLM Pipelines
by: Yang, Kang, et al.
Published: (2025)
by: Yang, Kang, et al.
Published: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation
by: Ye, Hengkai, et al.
Published: (2026)
by: Ye, Hengkai, et al.
Published: (2026)
Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols
by: Zavrak, Sultan
Published: (2026)
by: Zavrak, Sultan
Published: (2026)
VIGIL: Defending LLM Agents Against Tool Stream Injection via Verify-Before-Commit
by: Lin, Junda, et al.
Published: (2026)
by: Lin, Junda, et al.
Published: (2026)
Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents
by: Zhou, Kaiyu, et al.
Published: (2026)
by: Zhou, Kaiyu, et al.
Published: (2026)
Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
by: Chen, Xuan, et al.
Published: (2026)
by: Chen, Xuan, et al.
Published: (2026)
Governing Dynamic Capabilities: Cryptographic Binding and Reproducibility Verification for AI Agent Tool Use
by: Zhou, Ziling
Published: (2026)
by: Zhou, Ziling
Published: (2026)
Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
by: Maloyan, Narek, et al.
Published: (2026)
by: Maloyan, Narek, et al.
Published: (2026)
MCP Pitfall Lab: Exposing Developer Pitfalls in MCP Tool Server Security under Multi-Vector Attacks
by: Hao, Run, et al.
Published: (2026)
by: Hao, Run, et al.
Published: (2026)
Similar Items
-
MIP against Agent: Malicious Image Patches Hijacking Multimodal OS Agents
by: Aichberger, Lukas, et al.
Published: (2025) -
BiasBusters: Uncovering and Mitigating Tool Selection Bias in Large Language Models
by: Blankenstein, Thierry, et al.
Published: (2025) -
Prompt Injection Attack to Tool Selection in LLM Agents
by: Shi, Jiawen, et al.
Published: (2025) -
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026) -
Shh, don't say that! Domain Certification in LLMs
by: Emde, Cornelius, et al.
Published: (2025)