Beyond Max Tokens: Stealthy Resource Amplification via Tool Calling Chains in LLM Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Zhou, Kaiyu, Zheng, Yongsen, He, Yicheng, Xue, Meng, Gong, Xueluan, Wang, Yuji, Zhang, Xuanye, Lam, Kwok-Yan |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
by: Dong, Ben, et al.
Published: (2026)
by: Dong, Ben, et al.
Published: (2026)
PAPILLON: Efficient and Stealthy Fuzz Testing-Powered Jailbreaks for LLMs
by: Gong, Xueluan, et al.
Published: (2024)
by: Gong, Xueluan, et al.
Published: (2024)
Evaluating and Mitigating LLM-as-a-judge Bias in Communication Systems
by: Gao, Jiaxin, et al.
Published: (2025)
by: Gao, Jiaxin, et al.
Published: (2025)
LLMs Cannot Reliably Judge (Yet?): A Comprehensive Assessment on the Robustness of LLM-as-a-Judge
by: Li, Songze, et al.
Published: (2025)
by: Li, Songze, et al.
Published: (2025)
Hidden Data Privacy Breaches in Federated Learning
by: Gong, Xueluan, et al.
Published: (2024)
by: Gong, Xueluan, et al.
Published: (2024)
Plato's Form: Toward Backdoor Defense-as-a-Service for LLMs with Prototype Representations
by: Chen, Chen, et al.
Published: (2026)
by: Chen, Chen, et al.
Published: (2026)
Threats, Attacks, and Defenses in Machine Unlearning: A Survey
by: Liu, Ziyao, et al.
Published: (2024)
by: Liu, Ziyao, et al.
Published: (2024)
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026)
by: Hu, Yuepeng, et al.
Published: (2026)
Lexo: Eliminating Stealthy Supply-Chain Attacks via LLM-Assisted Program Regeneration
by: Lamprou, Evangelos, et al.
Published: (2025)
by: Lamprou, Evangelos, et al.
Published: (2025)
Causality Laundering: Denial-Feedback Leakage in Tool-Calling LLM Agents
by: Chinaei, Mohammad Hossein
Published: (2026)
by: Chinaei, Mohammad Hossein
Published: (2026)
The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again
by: Liu, Tong, et al.
Published: (2025)
by: Liu, Tong, et al.
Published: (2025)
SuperEar: Eavesdropping on Mobile Voice Calls via Stealthy Acoustic Metamaterials
by: Ning, Zhiyuan, et al.
Published: (2025)
by: Ning, Zhiyuan, et al.
Published: (2025)
Prompt Injection Attack to Tool Selection in LLM Agents
by: Shi, Jiawen, et al.
Published: (2025)
by: Shi, Jiawen, et al.
Published: (2025)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
by: Wu, Jiangrong, et al.
Published: (2026)
by: Wu, Jiangrong, et al.
Published: (2026)
Megatron: Evasive Clean-Label Backdoor Attacks against Vision Transformer
by: Gong, Xueluan, et al.
Published: (2024)
by: Gong, Xueluan, et al.
Published: (2024)
An Effective and Resilient Backdoor Attack Framework against Deep Neural Networks and Vision Transformers
by: Gong, Xueluan, et al.
Published: (2024)
by: Gong, Xueluan, et al.
Published: (2024)
TrojanDam: Detection-Free Backdoor Defense in Federated Learning through Proactive Model Robustification utilizing OOD Data
by: Dai, Yanbo, et al.
Published: (2025)
by: Dai, Yanbo, et al.
Published: (2025)
SynthChain: A Synthetic Benchmark and Forensic Analysis of Advanced and Stealthy Software Supply Chain Attacks
by: Tan, Zhuoran, et al.
Published: (2026)
by: Tan, Zhuoran, et al.
Published: (2026)
Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
by: Chen, Xuan, et al.
Published: (2026)
by: Chen, Xuan, et al.
Published: (2026)
Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification
by: Zhang, Boyang, et al.
Published: (2024)
by: Zhang, Boyang, et al.
Published: (2024)
Stealthy Targeted Backdoor Attacks against Image Captioning
by: Fan, Wenshu, et al.
Published: (2024)
by: Fan, Wenshu, et al.
Published: (2024)
URVFL: Undetectable Data Reconstruction Attack on Vertical Federated Learning
by: Yao, Duanyi, et al.
Published: (2024)
by: Yao, Duanyi, et al.
Published: (2024)
AEGIS: No Tool Call Left Unchecked -- A Pre-Execution Firewall and Audit Layer for AI Agents
by: Yuan, Aojie, et al.
Published: (2026)
by: Yuan, Aojie, et al.
Published: (2026)
Clouding the Mirror: Stealthy Prompt Injection Attacks Targeting LLM-based Phishing Detection
by: Koide, Takashi, et al.
Published: (2026)
by: Koide, Takashi, et al.
Published: (2026)
Imprompter: Tricking LLM Agents into Improper Tool Use
by: Fu, Xiaohan, et al.
Published: (2024)
by: Fu, Xiaohan, et al.
Published: (2024)
EverTracer: Hunting Stolen Large Language Models via Stealthy and Robust Probabilistic Fingerprint
by: Xu, Zhenhua, et al.
Published: (2025)
by: Xu, Zhenhua, et al.
Published: (2025)
Echoes within the Reasoning: Stealthy and Effective Watermarking via Chain of Thought
by: Lu, Jiacheng, et al.
Published: (2026)
by: Lu, Jiacheng, et al.
Published: (2026)
Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM Agents
by: Li, Zichuan, et al.
Published: (2025)
by: Li, Zichuan, et al.
Published: (2025)
Cuckoo Attack: Stealthy and Persistent Attacks Against AI-IDE
by: Liu, Xinpeng, et al.
Published: (2025)
by: Liu, Xinpeng, et al.
Published: (2025)
WebWeaver: Breaking Topology Confidentiality in LLM Multi-Agent Systems with Stealthy Context-Based Inference
by: Xiong, Zixun, et al.
Published: (2026)
by: Xiong, Zixun, et al.
Published: (2026)
UAV Resilience Against Stealthy Attacks
by: Amorim, Arthur, et al.
Published: (2025)
by: Amorim, Arthur, et al.
Published: (2025)
Sound Conveyors for Stealthy Data Transmission
by: Dassanayaka, Sachith
Published: (2025)
by: Dassanayaka, Sachith
Published: (2025)
From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection
by: Wang, Haowei, et al.
Published: (2024)
by: Wang, Haowei, et al.
Published: (2024)
Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools
by: Mohammadi, Bardia, et al.
Published: (2026)
by: Mohammadi, Bardia, et al.
Published: (2026)
MiniScope: A Least Privilege Framework for Authorizing Tool Calling Agents
by: Zhu, Jinhao, et al.
Published: (2025)
by: Zhu, Jinhao, et al.
Published: (2025)
Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents
by: Uchibeke, Uchi
Published: (2026)
by: Uchibeke, Uchi
Published: (2026)
Watermarking LLM Agent Trajectories
by: Meng, Wenlong, et al.
Published: (2026)
by: Meng, Wenlong, et al.
Published: (2026)
Is Monitoring Enough? Strategic Agent Selection For Stealthy Attack in Multi-Agent Discussions
by: Xiang, Qiuchi, et al.
Published: (2026)
by: Xiang, Qiuchi, et al.
Published: (2026)
DrunkAgent: Stealthy Memory Corruption in LLM-Powered Recommender Agents
by: Yang, Shiyi, et al.
Published: (2025)
by: Yang, Shiyi, et al.
Published: (2025)
AgentGuard: An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
by: Luo, Jiaqi, et al.
Published: (2026)
by: Luo, Jiaqi, et al.
Published: (2026)
Similar Items
-
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
by: Dong, Ben, et al.
Published: (2026) -
PAPILLON: Efficient and Stealthy Fuzz Testing-Powered Jailbreaks for LLMs
by: Gong, Xueluan, et al.
Published: (2024) -
Evaluating and Mitigating LLM-as-a-judge Bias in Communication Systems
by: Gao, Jiaxin, et al.
Published: (2025) -
LLMs Cannot Reliably Judge (Yet?): A Comprehensive Assessment on the Robustness of LLM-as-a-Judge
by: Li, Songze, et al.
Published: (2025) -
Hidden Data Privacy Breaches in Federated Learning
by: Gong, Xueluan, et al.
Published: (2024)