From Storage to Steering: Memory Control Flow Attacks on LLM Agents
Fuente:
arXiv
Guardado en:
| Autores principales: | Xu, Zhenlin, Zhu, Xiaogang, Yao, Yu, Xue, Minhui, Song, Yiliao |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems
por: Li, Fanxiao, et al.
Publicado: (2026)
por: Li, Fanxiao, et al.
Publicado: (2026)
Learn What You Want to Unlearn: Unlearning Inversion Attacks against Machine Unlearning
por: Hu, Hongsheng, et al.
Publicado: (2024)
por: Hu, Hongsheng, et al.
Publicado: (2024)
Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills
por: Liu, Yiyong, et al.
Publicado: (2026)
por: Liu, Yiyong, et al.
Publicado: (2026)
Memory Poisoning Attack and Defense on Memory Based LLM-Agents
por: Sunil, Balachandra Devarangadi, et al.
Publicado: (2026)
por: Sunil, Balachandra Devarangadi, et al.
Publicado: (2026)
Bones of Contention: Exploring Query-Efficient Attacks against Skeleton Recognition Systems
por: Cao, Yuxin, et al.
Publicado: (2025)
por: Cao, Yuxin, et al.
Publicado: (2025)
MalTool: Malicious Tool Attacks on LLM Agents
por: Hu, Yuepeng, et al.
Publicado: (2026)
por: Hu, Yuepeng, et al.
Publicado: (2026)
From LLMs to MLLMs to Agents: A Survey of Emerging Paradigms in Jailbreak Attacks and Defenses within LLM Ecosystem
por: Mao, Yanxu, et al.
Publicado: (2025)
por: Mao, Yanxu, et al.
Publicado: (2025)
Private Synthetic Data Generation in Bounded Memory
por: Holland, Rayne, et al.
Publicado: (2024)
por: Holland, Rayne, et al.
Publicado: (2024)
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
por: Wang, Yihan, et al.
Publicado: (2025)
por: Wang, Yihan, et al.
Publicado: (2025)
Black-Box Skill Stealing Attack from Proprietary LLM Agents: An Empirical Study
por: Wang, Zihan, et al.
Publicado: (2026)
por: Wang, Zihan, et al.
Publicado: (2026)
Evolving Skill-Structured Attack Memory Enhances LLM Jailbreaking
por: Zhang, Junke, et al.
Publicado: (2026)
por: Zhang, Junke, et al.
Publicado: (2026)
LoopTrap: Termination Poisoning Attacks on LLM Agents
por: Xu, Huiyu, et al.
Publicado: (2026)
por: Xu, Huiyu, et al.
Publicado: (2026)
Steering in the Shadows: Causal Amplification for Activation Space Attacks in Large Language Models
por: Xu, Zhiyuan, et al.
Publicado: (2025)
por: Xu, Zhiyuan, et al.
Publicado: (2025)
Red-Teaming LLM Multi-Agent Systems via Communication Attacks
por: He, Pengfei, et al.
Publicado: (2025)
por: He, Pengfei, et al.
Publicado: (2025)
Harmless Yet Harmful: Neutral Prompting Attacks for Stealthy Hallucination Steering in Agent Skills
por: Hsu, Chia-Yi, et al.
Publicado: (2026)
por: Hsu, Chia-Yi, et al.
Publicado: (2026)
Collaborative Shadows: Distributed Backdoor Attacks in LLM-Based Multi-Agent Systems
por: Zhu, Pengyu, et al.
Publicado: (2025)
por: Zhu, Pengyu, et al.
Publicado: (2025)
Prompt Injection Attack to Tool Selection in LLM Agents
por: Shi, Jiawen, et al.
Publicado: (2025)
por: Shi, Jiawen, et al.
Publicado: (2025)
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
por: Liu, Hanzhi, et al.
Publicado: (2026)
por: Liu, Hanzhi, et al.
Publicado: (2026)
AgentRAE: Remote Action Execution through Notification-based Visual Backdoors against Screenshots-based Mobile GUI Agents
por: Luo, Yutao, et al.
Publicado: (2026)
por: Luo, Yutao, et al.
Publicado: (2026)
Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents
por: Cai, Yuandao, et al.
Publicado: (2026)
por: Cai, Yuandao, et al.
Publicado: (2026)
CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM Agent
por: Ning, Liang-bo, et al.
Publicado: (2025)
por: Ning, Liang-bo, et al.
Publicado: (2025)
Towards Strengthening Deep Learning-based Side Channel Attacks with Mixup
por: Luo, Zhimin, et al.
Publicado: (2021)
por: Luo, Zhimin, et al.
Publicado: (2021)
Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents
por: Wu, Jiangrong, et al.
Publicado: (2025)
por: Wu, Jiangrong, et al.
Publicado: (2025)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
por: Han, Junxiao, et al.
Publicado: (2025)
por: Han, Junxiao, et al.
Publicado: (2025)
DrunkAgent: Stealthy Memory Corruption in LLM-Powered Recommender Agents
por: Yang, Shiyi, et al.
Publicado: (2025)
por: Yang, Shiyi, et al.
Publicado: (2025)
Adversarial Attacks on Reinforcement Learning Agents for Command and Control
por: Dabholkar, Ahaan, et al.
Publicado: (2024)
por: Dabholkar, Ahaan, et al.
Publicado: (2024)
Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction
por: Wang, Hongtao, et al.
Publicado: (2026)
por: Wang, Hongtao, et al.
Publicado: (2026)
Observable Channels, Not Just Storage: Evaluating Privacy Leakage in LLM Agent Pipelines
por: Huang, Tao, et al.
Publicado: (2026)
por: Huang, Tao, et al.
Publicado: (2026)
SoK: The Security-Safety Continuum of Multimodal Foundation Models through Information Flow and Global Game-Theoretic Analysis of Asymmetric Threats
por: Sun, Ruoxi, et al.
Publicado: (2024)
por: Sun, Ruoxi, et al.
Publicado: (2024)
Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
por: Zhang, Hanrong, et al.
Publicado: (2024)
por: Zhang, Hanrong, et al.
Publicado: (2024)
MemoPhishAgent: Memory-Augmented Multi-Modal LLM Agent for Phishing URL Detection
por: Chen, Xuan, et al.
Publicado: (2026)
por: Chen, Xuan, et al.
Publicado: (2026)
The Invisible Game on the Internet: A Case Study of Decoding Deceptive Patterns
por: Shi, Zewei, et al.
Publicado: (2024)
por: Shi, Zewei, et al.
Publicado: (2024)
DemonAgent: Dynamically Encrypted Multi-Backdoor Implantation Attack on LLM-based Agent
por: Zhu, Pengyu, et al.
Publicado: (2025)
por: Zhu, Pengyu, et al.
Publicado: (2025)
Enhancing LLM-based Autonomous Driving Agents to Mitigate Perception Attacks
por: Song, Ruoyu, et al.
Publicado: (2024)
por: Song, Ruoyu, et al.
Publicado: (2024)
MRMMIA: Membership Inference Attacks on Memory in Chat Agents
por: Chen, Kai, et al.
Publicado: (2026)
por: Chen, Kai, et al.
Publicado: (2026)
CyberSleuth: Autonomous Blue-Team LLM Agent for Web Attack Forensics
por: Fumero, Stefano, et al.
Publicado: (2025)
por: Fumero, Stefano, et al.
Publicado: (2025)
AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
por: He, Yu, et al.
Publicado: (2026)
por: He, Yu, et al.
Publicado: (2026)
The Vulnerability of LLM Rankers to Prompt Injection Attacks
por: Yin, Yu, et al.
Publicado: (2026)
por: Yin, Yu, et al.
Publicado: (2026)
Securing LLM Agents Need Intent-to-Execution Integrity
por: Qu, Wenjie, et al.
Publicado: (2026)
por: Qu, Wenjie, et al.
Publicado: (2026)
AttackLLM: LLM-based Attack Pattern Generation for an Industrial Control System
por: Ahmed, Chuadhry Mujeeb
Publicado: (2025)
por: Ahmed, Chuadhry Mujeeb
Publicado: (2025)
Ejemplares similares
-
FlowSteer: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems
por: Li, Fanxiao, et al.
Publicado: (2026) -
Learn What You Want to Unlearn: Unlearning Inversion Attacks against Machine Unlearning
por: Hu, Hongsheng, et al.
Publicado: (2024) -
Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills
por: Liu, Yiyong, et al.
Publicado: (2026) -
Memory Poisoning Attack and Defense on Memory Based LLM-Agents
por: Sunil, Balachandra Devarangadi, et al.
Publicado: (2026) -
Bones of Contention: Exploring Query-Efficient Attacks against Skeleton Recognition Systems
por: Cao, Yuxin, et al.
Publicado: (2025)