MURMUR: Using cross-user chatter to break collaborative language agents in groups

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Patlan, Atharv Singh, Sheng, Peiyao, Hebbar, S. Ashwin, Mittal, Prateek, Viswanath, Pramod
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912724390248448
author Patlan, Atharv Singh
Sheng, Peiyao
Hebbar, S. Ashwin
Mittal, Prateek
Viswanath, Pramod
author_facet Patlan, Atharv Singh
Sheng, Peiyao
Hebbar, S. Ashwin
Mittal, Prateek
Viswanath, Pramod
contents Language agents are rapidly expanding from single-user assistants to multi-user collaborators in shared workspaces and groups. However, today's language models lack a mechanism for isolating user interactions and concurrent tasks, creating a new attack vector inherent to this new setting: cross-user poisoning (CUP). In a CUP attack, an adversary injects ordinary-looking messages that poison the persistent, shared state, which later triggers the agent to execute unintended, attacker-specified actions on behalf of benign users. We validate CUP on real systems, successfully attacking popular multi-user agents. To study the phenomenon systematically, we present MURMUR, a framework that composes single-user tasks into concurrent, group-based scenarios using an LLM to generate realistic, history-aware user interactions. We observe that CUP attacks succeed at high rates and their effects persist across multiple tasks, thus posing fundamental risks to multi-user LLM deployments. Finally, we introduce a first-step defense with task-based clustering to mitigate this new class of vulnerability
format Preprint
id arxiv_https___arxiv_org_abs_2511_17671
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MURMUR: Using cross-user chatter to break collaborative language agents in groups
Patlan, Atharv Singh
Sheng, Peiyao
Hebbar, S. Ashwin
Mittal, Prateek
Viswanath, Pramod
Cryptography and Security
Artificial Intelligence
Computation and Language
Language agents are rapidly expanding from single-user assistants to multi-user collaborators in shared workspaces and groups. However, today's language models lack a mechanism for isolating user interactions and concurrent tasks, creating a new attack vector inherent to this new setting: cross-user poisoning (CUP). In a CUP attack, an adversary injects ordinary-looking messages that poison the persistent, shared state, which later triggers the agent to execute unintended, attacker-specified actions on behalf of benign users. We validate CUP on real systems, successfully attacking popular multi-user agents. To study the phenomenon systematically, we present MURMUR, a framework that composes single-user tasks into concurrent, group-based scenarios using an LLM to generate realistic, history-aware user interactions. We observe that CUP attacks succeed at high rates and their effects persist across multiple tasks, thus posing fundamental risks to multi-user LLM deployments. Finally, we introduce a first-step defense with task-based clustering to mitigate this new class of vulnerability
title MURMUR: Using cross-user chatter to break collaborative language agents in groups
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2511.17671