MalTool: Malicious Tool Attacks on LLM Agents
Fuente:
arXiv
Guardado en:
| Autores principales: | Hu, Yuepeng, Jia, Yuqi, Li, Mengyuan, Song, Dawn, Gong, Neil |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Evaluating Tool Cloning in Agentic-AI Ecosystems
por: Kim, Taein, et al.
Publicado: (2026)
por: Kim, Taein, et al.
Publicado: (2026)
Prompt Injection Attack to Tool Selection in LLM Agents
por: Shi, Jiawen, et al.
Publicado: (2025)
por: Shi, Jiawen, et al.
Publicado: (2025)
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
por: Wang, Reachal, et al.
Publicado: (2025)
por: Wang, Reachal, et al.
Publicado: (2025)
DataSentinel: A Game-Theoretic Detection of Prompt Injection Attacks
por: Liu, Yupei, et al.
Publicado: (2025)
por: Liu, Yupei, et al.
Publicado: (2025)
Tracing Back the Malicious Clients in Poisoning Attacks to Federated Learning
por: Jia, Yuqi, et al.
Publicado: (2024)
por: Jia, Yuqi, et al.
Publicado: (2024)
A Critical Evaluation of Defenses against Prompt Injection Attacks
por: Jia, Yuqi, et al.
Publicado: (2025)
por: Jia, Yuqi, et al.
Publicado: (2025)
ToolTweak: An Attack on Tool Selection in LLM-based Agents
por: Sneh, Jonathan, et al.
Publicado: (2025)
por: Sneh, Jonathan, et al.
Publicado: (2025)
Evaluating LLM-based Personal Information Extraction and Countermeasures
por: Liu, Yupei, et al.
Publicado: (2024)
por: Liu, Yupei, et al.
Publicado: (2024)
Competitive Advantage Attacks to Decentralized Federated Learning
por: Jia, Yuqi, et al.
Publicado: (2023)
por: Jia, Yuqi, et al.
Publicado: (2023)
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
por: Zhang, Mohan, et al.
Publicado: (2026)
por: Zhang, Mohan, et al.
Publicado: (2026)
AlignSentinel: Alignment-Aware Detection of Prompt Injection Attacks
por: Jia, Yuqi, et al.
Publicado: (2026)
por: Jia, Yuqi, et al.
Publicado: (2026)
MalModel: Hiding Malicious Payload in Mobile Deep Learning Models with Black-box Backdoor Attack
por: Hua, Jiayi, et al.
Publicado: (2024)
por: Hua, Jiayi, et al.
Publicado: (2024)
A Transfer Attack to Image Watermarks
por: Hu, Yuepeng, et al.
Publicado: (2024)
por: Hu, Yuepeng, et al.
Publicado: (2024)
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
por: Liu, Hanzhi, et al.
Publicado: (2026)
por: Liu, Hanzhi, et al.
Publicado: (2026)
Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM Agents
por: Li, Zichuan, et al.
Publicado: (2025)
por: Li, Zichuan, et al.
Publicado: (2025)
PromptLocate: Localizing Prompt Injection Attacks
por: Jia, Yuqi, et al.
Publicado: (2025)
por: Jia, Yuqi, et al.
Publicado: (2025)
Fingerprinting LLMs via Prompt Injection
por: Hu, Yuepeng, et al.
Publicado: (2025)
por: Hu, Yuepeng, et al.
Publicado: (2025)
WebSentinel: Detecting and Localizing Prompt Injection Attacks for Web Agents
por: Wang, Xilong, et al.
Publicado: (2026)
por: Wang, Xilong, et al.
Publicado: (2026)
Memory-Induced Tool-Drift in LLM Agents
por: Dabas, Mahavir, et al.
Publicado: (2026)
por: Dabas, Mahavir, et al.
Publicado: (2026)
Imprompter: Tricking LLM Agents into Improper Tool Use
por: Fu, Xiaohan, et al.
Publicado: (2024)
por: Fu, Xiaohan, et al.
Publicado: (2024)
A Framework for Formalizing LLM Agent Security
por: Siu, Vincent, et al.
Publicado: (2026)
por: Siu, Vincent, et al.
Publicado: (2026)
MalRAG: A Retrieval-Augmented LLM Framework for Open-set Malicious Traffic Identification
por: Luo, Xiang, et al.
Publicado: (2025)
por: Luo, Xiang, et al.
Publicado: (2025)
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback
por: Yan, Lecheng, et al.
Publicado: (2026)
por: Yan, Lecheng, et al.
Publicado: (2026)
TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation
por: Ye, Hengkai, et al.
Publicado: (2026)
por: Ye, Hengkai, et al.
Publicado: (2026)
CleanBase: Detecting Malicious Documents in RAG Knowledge Databases
por: Jin, Weifei, et al.
Publicado: (2026)
por: Jin, Weifei, et al.
Publicado: (2026)
SafeText: Safe Text-to-image Models via Aligning the Text Encoder
por: Hu, Yuepeng, et al.
Publicado: (2025)
por: Hu, Yuepeng, et al.
Publicado: (2025)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
por: Sun, Tiezhu, et al.
Publicado: (2025)
por: Sun, Tiezhu, et al.
Publicado: (2025)
Security Attacks on LLM-based Code Completion Tools
por: Cheng, Wen, et al.
Publicado: (2024)
por: Cheng, Wen, et al.
Publicado: (2024)
SINCon: Mitigate LLM-Generated Malicious Message Injection Attack for Rumor Detection
por: Zhang, Mingqing, et al.
Publicado: (2025)
por: Zhang, Mingqing, et al.
Publicado: (2025)
Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills
por: Liu, Yiyong, et al.
Publicado: (2026)
por: Liu, Yiyong, et al.
Publicado: (2026)
PotentRegion4MalDetect: Advanced Features from Potential Malicious Regions for Malware Detection
por: Koppanati, Rama Krishna, et al.
Publicado: (2025)
por: Koppanati, Rama Krishna, et al.
Publicado: (2025)
MalGuard: Towards Real-Time, Accurate, and Actionable Detection of Malicious Packages in PyPI Ecosystem
por: Gao, Xingan, et al.
Publicado: (2025)
por: Gao, Xingan, et al.
Publicado: (2025)
AgentGuard: An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
por: Luo, Jiaqi, et al.
Publicado: (2026)
por: Luo, Jiaqi, et al.
Publicado: (2026)
Stable Signature is Unstable: Removing Image Watermark from Diffusion Models
por: Hu, Yuepeng, et al.
Publicado: (2024)
por: Hu, Yuepeng, et al.
Publicado: (2024)
Preventing Jailbreak Prompts as Malicious Tools for Cybercriminals: A Cyber Defense Perspective
por: Tshimula, Jean Marie, et al.
Publicado: (2024)
por: Tshimula, Jean Marie, et al.
Publicado: (2024)
DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial Purification
por: Kang, Mintong, et al.
Publicado: (2023)
por: Kang, Mintong, et al.
Publicado: (2023)
Select Me! When You Need a Tool: A Black-box Text Attack on Tool Selection
por: Chen, Liuji, et al.
Publicado: (2025)
por: Chen, Liuji, et al.
Publicado: (2025)
The Verifier Tax: Horizon Dependent Safety Success Tradeoffs in Tool Using LLM Agents
por: Sah, Tanmay, et al.
Publicado: (2026)
por: Sah, Tanmay, et al.
Publicado: (2026)
Attack Effect Model based Malicious Behavior Detection
por: Wang, Limin, et al.
Publicado: (2025)
por: Wang, Limin, et al.
Publicado: (2025)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
por: He, Yu, et al.
Publicado: (2026)
por: He, Yu, et al.
Publicado: (2026)
Ejemplares similares
-
Evaluating Tool Cloning in Agentic-AI Ecosystems
por: Kim, Taein, et al.
Publicado: (2026) -
Prompt Injection Attack to Tool Selection in LLM Agents
por: Shi, Jiawen, et al.
Publicado: (2025) -
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
por: Wang, Reachal, et al.
Publicado: (2025) -
DataSentinel: A Game-Theoretic Detection of Prompt Injection Attacks
por: Liu, Yupei, et al.
Publicado: (2025) -
Tracing Back the Malicious Clients in Poisoning Attacks to Federated Learning
por: Jia, Yuqi, et al.
Publicado: (2024)