Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Kaiyu, Zheng, Yongsen, He, Yicheng, Xue, Meng, Gong, Xueluan, Wang, Yuji, Zhang, Xuanye, Lam, Kwok-Yan
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911505517117440
author Zhou, Kaiyu
Zheng, Yongsen
He, Yicheng
Xue, Meng
Gong, Xueluan
Wang, Yuji
Zhang, Xuanye
Lam, Kwok-Yan
author_facet Zhou, Kaiyu
Zheng, Yongsen
He, Yicheng
Xue, Meng
Gong, Xueluan
Wang, Yuji
Zhang, Xuanye
Lam, Kwok-Yan
contents The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents. Existing denial-of-service (DoS) attacks typically function at the user-prompt or retrieval-augmented generation (RAG) context layer and are inherently single-turn in nature. This limitation restricts cost amplification and diminishes stealth in goal-oriented workflows. To address these issues, we proposed a stealthy, multi-turn economic DoS attack at the tool layer under the Model Context Protocol (MCP). By simply editing text-visible fields and implementing a template-driven return policy, our malicious server preserves function signatures and the terminal benign payload while steering agents into prolonged, verbose tool-calling chains. We optimize these text-only edits with Monte Carlo Tree Search (MCTS) to maximize cost under a task-success constraint. Across six LLMs on ToolBench and BFCL benchmarks, our attack yields trajectories over 60K tokens, increases per-query cost by up to 658 times, raises energy by 100 to 560 times, and pushes GPU key-value (KV) cache occupancy to 35--74%. Standard prompt filters and output trajectory monitors seldom detect these attacks, highlighting the need for defenses that safeguard agentic processes rather than focusing solely on final outcomes. We will release the code soon.
format Preprint
id arxiv_https___arxiv_org_abs_2601_10955
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents
Zhou, Kaiyu
Zheng, Yongsen
He, Yicheng
Xue, Meng
Gong, Xueluan
Wang, Yuji
Zhang, Xuanye
Lam, Kwok-Yan
Cryptography and Security
Artificial Intelligence
The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents. Existing denial-of-service (DoS) attacks typically function at the user-prompt or retrieval-augmented generation (RAG) context layer and are inherently single-turn in nature. This limitation restricts cost amplification and diminishes stealth in goal-oriented workflows. To address these issues, we proposed a stealthy, multi-turn economic DoS attack at the tool layer under the Model Context Protocol (MCP). By simply editing text-visible fields and implementing a template-driven return policy, our malicious server preserves function signatures and the terminal benign payload while steering agents into prolonged, verbose tool-calling chains. We optimize these text-only edits with Monte Carlo Tree Search (MCTS) to maximize cost under a task-success constraint. Across six LLMs on ToolBench and BFCL benchmarks, our attack yields trajectories over 60K tokens, increases per-query cost by up to 658 times, raises energy by 100 to 560 times, and pushes GPU key-value (KV) cache occupancy to 35--74%. Standard prompt filters and output trajectory monitors seldom detect these attacks, highlighting the need for defenses that safeguard agentic processes rather than focusing solely on final outcomes. We will release the code soon.
title Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2601.10955