Don't Trust Your Upstream: Exploiting LLM Multi-Agent System via Topology-Guided Adversarial Propagation
Fuente:
arXiv
Guardado en:
| Autores principales: | Liang, Ruichao, Yin, Le, Chen, Jing, Feng, Yebo, Wu, Cong, Zhang, Xiaoyu, Gu, Huangpeng, Zhang, Zijian, Liu, Yang |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
EvoPoC: Automated Exploit Synthesis for DeFi Smart Contracts via Hierarchical Knowledge Graphs
por: Liang, Ruichao, et al.
Publicado: (2026)
por: Liang, Ruichao, et al.
Publicado: (2026)
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
por: Shan, Zhengyang, et al.
Publicado: (2026)
por: Shan, Zhengyang, et al.
Publicado: (2026)
Don't Click That: Teaching Web Agents to Resist Deceptive Interfaces
por: Zhang, Yilin, et al.
Publicado: (2026)
por: Zhang, Yilin, et al.
Publicado: (2026)
Babel: Jailbreaking Safety Attention via Obfuscation Distribution Optimized Sampling
por: Wang, Ziwei, et al.
Publicado: (2026)
por: Wang, Ziwei, et al.
Publicado: (2026)
Semantic Sleuth: Identifying Ponzi Contracts via Large Language Models
por: Wu, Cong, et al.
Publicado: (2024)
por: Wu, Cong, et al.
Publicado: (2024)
Data Reconstruction: When You See It and When You Don't
por: Cohen, Edith, et al.
Publicado: (2024)
por: Cohen, Edith, et al.
Publicado: (2024)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
por: Pan, Shidong, et al.
Publicado: (2024)
por: Pan, Shidong, et al.
Publicado: (2024)
Sealing the Audit-Runtime Gap for LLM Skills
por: Shen, Tingda, et al.
Publicado: (2026)
por: Shen, Tingda, et al.
Publicado: (2026)
Benchmarking LLMs and LLM-based Agents in Practical Vulnerability Detection for Code Repositories
por: Yildiz, Alperen, et al.
Publicado: (2025)
por: Yildiz, Alperen, et al.
Publicado: (2025)
Generalized Adversarial Code-Suggestions: Exploiting Contexts of LLM-based Code-Completion
por: Rubel, Karl, et al.
Publicado: (2024)
por: Rubel, Karl, et al.
Publicado: (2024)
SoK: Trust-Authorization Mismatch in LLM Agent Interactions
por: Shi, Guanquan, et al.
Publicado: (2025)
por: Shi, Guanquan, et al.
Publicado: (2025)
Don't Forget Too Much: Towards Machine Unlearning on Feature Level
por: Xu, Heng, et al.
Publicado: (2024)
por: Xu, Heng, et al.
Publicado: (2024)
If You Don't Understand It, Don't Use It: Eliminating Trojans with Filters Between Layers
por: Hernandez, Adriano
Publicado: (2024)
por: Hernandez, Adriano
Publicado: (2024)
Identifying Adversary Tactics and Techniques in Malware Binaries with an LLM Agent
por: Xuan, Zhou, et al.
Publicado: (2026)
por: Xuan, Zhou, et al.
Publicado: (2026)
Benchmarking ZK-Friendly Hash Functions and SNARK Proving Systems for EVM-compatible Blockchains
por: Guo, Hanze, et al.
Publicado: (2024)
por: Guo, Hanze, et al.
Publicado: (2024)
RECUR: Resource Exhaustion Attack via Recursive-Entropy Guided Counterfactual Utilization and Reflection
por: Wang, Ziwei, et al.
Publicado: (2026)
por: Wang, Ziwei, et al.
Publicado: (2026)
Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security
por: Albrecht, Jannik, et al.
Publicado: (2024)
por: Albrecht, Jannik, et al.
Publicado: (2024)
Please Don't Kill My Vibe: Empowering Agents with Data Flow Control
por: Summers, Charlie, et al.
Publicado: (2025)
por: Summers, Charlie, et al.
Publicado: (2025)
Prompts Don't Protect: Architectural Enforcement via MCP Proxy for LLM Tool Access Control
por: Uppala, Rohith
Publicado: (2026)
por: Uppala, Rohith
Publicado: (2026)
Your LLM Agent Can Leak Your Data: Data Exfiltration via Backdoored Tool Use
por: Zhang, Wuyang, et al.
Publicado: (2026)
por: Zhang, Wuyang, et al.
Publicado: (2026)
Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models
por: Yu, Zhiyuan, et al.
Publicado: (2024)
por: Yu, Zhiyuan, et al.
Publicado: (2024)
Don't Hash Me Like That: Exposing and Mitigating Hash-Induced Unfairness in Local Differential Privacy
por: Balioglu, Berkay Kemal, et al.
Publicado: (2025)
por: Balioglu, Berkay Kemal, et al.
Publicado: (2025)
The Trust Paradox in LLM-Based Multi-Agent Systems: When Collaboration Becomes a Security Vulnerability
por: Xu, Zijie, et al.
Publicado: (2025)
por: Xu, Zijie, et al.
Publicado: (2025)
MagLive: Robust Voice Liveness Detection on Smartphones Using Magnetic Pattern Changes
por: Sun, Xiping, et al.
Publicado: (2024)
por: Sun, Xiping, et al.
Publicado: (2024)
SCR-Auth: Secure Call Receiver Authentication on Smartphones Using Outer Ear Echoes
por: Sun, Xiping, et al.
Publicado: (2024)
por: Sun, Xiping, et al.
Publicado: (2024)
Hide Your Malicious Goal Into Benign Narratives: Jailbreak Large Language Models through Carrier Articles
por: Wang, Zhilong, et al.
Publicado: (2024)
por: Wang, Zhilong, et al.
Publicado: (2024)
"Explain, Don't Just Warn!" -- A Real-Time Framework for Generating Phishing Warnings with Contextual Cues
por: Roy, Sayak Saha, et al.
Publicado: (2025)
por: Roy, Sayak Saha, et al.
Publicado: (2025)
To trust or not to trust: Attention-based Trust Management for LLM Multi-Agent Systems
por: He, Pengfei, et al.
Publicado: (2025)
por: He, Pengfei, et al.
Publicado: (2025)
I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors
por: Lin, Zijin, et al.
Publicado: (2024)
por: Lin, Zijin, et al.
Publicado: (2024)
CompressionAttack: Exploiting Prompt Compression as a New Attack Surface in LLM-Powered Agents
por: Liu, Zesen, et al.
Publicado: (2025)
por: Liu, Zesen, et al.
Publicado: (2025)
LLM Cyber Evaluations Don't Capture Real-World Risk
por: Lukošiūtė, Kamilė, et al.
Publicado: (2025)
por: Lukošiūtė, Kamilė, et al.
Publicado: (2025)
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
por: Liu, Hanzhi, et al.
Publicado: (2026)
por: Liu, Hanzhi, et al.
Publicado: (2026)
When Safe Models Merge into Danger: Exploiting Latent Vulnerabilities in LLM Fusion
por: Li, Jiaqing, et al.
Publicado: (2026)
por: Li, Jiaqing, et al.
Publicado: (2026)
TZ-LLM: Protecting On-Device Large Language Models with Arm TrustZone
por: Wang, Xunjie, et al.
Publicado: (2025)
por: Wang, Xunjie, et al.
Publicado: (2025)
Exploiting AI for Attacks: On the Interplay between Adversarial AI and Offensive AI
por: Schröer, Saskia Laura, et al.
Publicado: (2025)
por: Schröer, Saskia Laura, et al.
Publicado: (2025)
Hallucination as Exploit: Evidence-Carrying Multimodal Agents
por: Zhang, Guijia, et al.
Publicado: (2026)
por: Zhang, Guijia, et al.
Publicado: (2026)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
por: Li, Zhihao, et al.
Publicado: (2026)
por: Li, Zhihao, et al.
Publicado: (2026)
TrustConnect: An In-Vehicle Anomaly Detection Framework through Topology-Based Trust Rating
por: Roy, Ayan, et al.
Publicado: (2025)
por: Roy, Ayan, et al.
Publicado: (2025)
LLM Agents can Autonomously Exploit One-day Vulnerabilities
por: Fang, Richard, et al.
Publicado: (2024)
por: Fang, Richard, et al.
Publicado: (2024)
AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
por: Li, Hao, et al.
Publicado: (2026)
por: Li, Hao, et al.
Publicado: (2026)
Ejemplares similares
-
EvoPoC: Automated Exploit Synthesis for DeFi Smart Contracts via Hierarchical Knowledge Graphs
por: Liang, Ruichao, et al.
Publicado: (2026) -
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
por: Shan, Zhengyang, et al.
Publicado: (2026) -
Don't Click That: Teaching Web Agents to Resist Deceptive Interfaces
por: Zhang, Yilin, et al.
Publicado: (2026) -
Babel: Jailbreaking Safety Attention via Obfuscation Distribution Optimized Sampling
por: Wang, Ziwei, et al.
Publicado: (2026) -
Semantic Sleuth: Identifying Ponzi Contracts via Large Language Models
por: Wu, Cong, et al.
Publicado: (2024)