No Attacker Needed: Unintentional Cross-User Contamination in Shared-State LLM Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Yang, Tiankai, Li, Jiate, Nian, Yi, Dong, Shen, Xu, Ruiyao, Rossi, Ryan, Ding, Kaize, Zhao, Yue |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Agent Audit: A Security Analysis System for LLM Agent Applications
by: Zhang, Haiyue, et al.
Published: (2026)
by: Zhang, Haiyue, et al.
Published: (2026)
"Someone Hid It": Query-Agnostic Black-Box Attacks on LLM-Based Retrieval
by: Li, Jiate, et al.
Published: (2026)
by: Li, Jiate, et al.
Published: (2026)
The Blind Spot of Agent Safety: How Benign User Instructions Expose Critical Vulnerabilities in Computer-Use Agents
by: Ding, Xuwei, et al.
Published: (2026)
by: Ding, Xuwei, et al.
Published: (2026)
AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic Certification
by: Li, Jiate, et al.
Published: (2025)
by: Li, Jiate, et al.
Published: (2025)
Next-Generation Phishing: How LLM Agents Empower Cyber Attackers
by: Afane, Khalifa, et al.
Published: (2024)
by: Afane, Khalifa, et al.
Published: (2024)
A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives
by: Zhao, Kaixiang, et al.
Published: (2025)
by: Zhao, Kaixiang, et al.
Published: (2025)
A Descriptive Model for Modelling Attacker Decision-Making in Cyber-Deception
by: Turner, B. R., et al.
Published: (2025)
by: Turner, B. R., et al.
Published: (2025)
Attacker Control and Bug Prioritization
by: Lacombe, Guilhem, et al.
Published: (2025)
by: Lacombe, Guilhem, et al.
Published: (2025)
PAnDA: Rethinking Metric Differential Privacy Optimization at Scale with Anchor-Based Approximation
by: Liu, Ruiyao, et al.
Published: (2025)
by: Liu, Ruiyao, et al.
Published: (2025)
Provably Robust Explainable Graph Neural Networks against Graph Perturbation Attacks
by: Li, Jiate, et al.
Published: (2025)
by: Li, Jiate, et al.
Published: (2025)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
Infrastructure for Valuable, Tradable, and Verifiable Agent Memory
by: Li, Mengyuan, et al.
Published: (2026)
by: Li, Mengyuan, et al.
Published: (2026)
Red-Teaming LLM Multi-Agent Systems via Communication Attacks
by: He, Pengfei, et al.
Published: (2025)
by: He, Pengfei, et al.
Published: (2025)
Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary Perturbations
by: Li, Jiate, et al.
Published: (2025)
by: Li, Jiate, et al.
Published: (2025)
Securing LLM Agents Need Intent-to-Execution Integrity
by: Qu, Wenjie, et al.
Published: (2026)
by: Qu, Wenjie, et al.
Published: (2026)
That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality Applications
by: Slocum, Carter, et al.
Published: (2023)
by: Slocum, Carter, et al.
Published: (2023)
A Survey on Model Extraction Attacks and Defenses for Large Language Models
by: Zhao, Kaixiang, et al.
Published: (2025)
by: Zhao, Kaixiang, et al.
Published: (2025)
A Survey of Model Extraction Attacks and Defenses in Distributed Computing Environments
by: Zhao, Kaixiang, et al.
Published: (2025)
by: Zhao, Kaixiang, et al.
Published: (2025)
Forecasting Attacker Actions using Alert-driven Attack Graphs
by: Băbălău, Ion, et al.
Published: (2024)
by: Băbălău, Ion, et al.
Published: (2024)
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
by: Rahman, Md Rayhanur, et al.
Published: (2024)
by: Rahman, Md Rayhanur, et al.
Published: (2024)
Practicable Black-box Evasion Attacks on Link Prediction in Dynamic Graphs -- A Graph Sequential Embedding Method
by: Li, Jiate, et al.
Published: (2024)
by: Li, Jiate, et al.
Published: (2024)
Steering Externalities: Benign Activation Steering Unintentionally Increases Jailbreak Risk for Large Language Models
by: Xiong, Chen, et al.
Published: (2026)
by: Xiong, Chen, et al.
Published: (2026)
ToDA: Target-oriented Diffusion Attacker against Recommendation System
by: Liu, Xiaohao, et al.
Published: (2024)
by: Liu, Xiaohao, et al.
Published: (2024)
CARE: Ensemble Adversarial Robustness Evaluation Against Adaptive Attackers for Security Applications
by: Zhang, Hangsheng, et al.
Published: (2024)
by: Zhang, Hangsheng, et al.
Published: (2024)
ARCANE: Cross-Campaign Attacker Re-identification via Passive Beacon Telemetry -- A Bayesian Network Framework for Longitudinal Cyber Attribution
by: Weinberg, Abraham Itzhak
Published: (2026)
by: Weinberg, Abraham Itzhak
Published: (2026)
Hidden Secrets in the arXiv: Discovering, Analyzing, and Preventing Unintentional Information Disclosure in Source Files of Scientific Preprints
by: Pennekamp, Jan, et al.
Published: (2026)
by: Pennekamp, Jan, et al.
Published: (2026)
Graph Neural Network Explanations are Fragile
by: Li, Jiate, et al.
Published: (2024)
by: Li, Jiate, et al.
Published: (2024)
Selfish Mining in Multi-Attacker Scenarios: An Empirical Evaluation of Nakamoto, Fruitchain, and Strongchain
by: Perešíni, Martin, et al.
Published: (2026)
by: Perešíni, Martin, et al.
Published: (2026)
PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
by: Shen, Xiangmin, et al.
Published: (2024)
by: Shen, Xiangmin, et al.
Published: (2024)
Defending Against Intelligent Attackers at Large Scales
by: Lohn, Andrew J.
Published: (2025)
by: Lohn, Andrew J.
Published: (2025)
Quantum Disruption: An SOK of How Post-Quantum Attackers Reshape Blockchain Security and Performance
by: Mallick, Tushin, et al.
Published: (2025)
by: Mallick, Tushin, et al.
Published: (2025)
A Game Between the Defender and the Attacker for Trigger-based Black-box Model Watermarking
by: Huang, Chaoyue, et al.
Published: (2025)
by: Huang, Chaoyue, et al.
Published: (2025)
Protocol Agent: What If Agents Could Use Cryptography In Everyday Life?
by: De Rossi, Marco
Published: (2026)
by: De Rossi, Marco
Published: (2026)
HoneyTrap: Deceiving Large Language Model Attackers to Honeypot Traps with Resilient Multi-Agent Defense
by: Li, Siyuan, et al.
Published: (2026)
by: Li, Siyuan, et al.
Published: (2026)
Time-Efficient Locally Relevant Geo-Location Privacy Protection
by: Qiu, Chenxi, et al.
Published: (2024)
by: Qiu, Chenxi, et al.
Published: (2024)
CyberSleuth: Autonomous Blue-Team LLM Agent for Web Attack Forensics
by: Fumero, Stefano, et al.
Published: (2025)
by: Fumero, Stefano, et al.
Published: (2025)
Exposing LLM User Privacy via Traffic Fingerprint Analysis: A Study of Privacy Risks in LLM Agent Interactions
by: Zhang, Yixiang, et al.
Published: (2025)
by: Zhang, Yixiang, et al.
Published: (2025)
Automated Penetration Testing with LLM Agents and Classical Planning
by: Wang, Lingzhi, et al.
Published: (2025)
by: Wang, Lingzhi, et al.
Published: (2025)
Resilience and Security of Deep Neural Networks Against Intentional and Unintentional Perturbations: Survey and Research Challenges
by: Sayyed, Sazzad, et al.
Published: (2024)
by: Sayyed, Sazzad, et al.
Published: (2024)
When Skills Lie: Hidden-Comment Injection in LLM Agents
by: Wang, Qianli, et al.
Published: (2026)
by: Wang, Qianli, et al.
Published: (2026)
Similar Items
-
Agent Audit: A Security Analysis System for LLM Agent Applications
by: Zhang, Haiyue, et al.
Published: (2026) -
"Someone Hid It": Query-Agnostic Black-Box Attacks on LLM-Based Retrieval
by: Li, Jiate, et al.
Published: (2026) -
The Blind Spot of Agent Safety: How Benign User Instructions Expose Critical Vulnerabilities in Computer-Use Agents
by: Ding, Xuwei, et al.
Published: (2026) -
AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic Certification
by: Li, Jiate, et al.
Published: (2025) -
Next-Generation Phishing: How LLM Agents Empower Cyber Attackers
by: Afane, Khalifa, et al.
Published: (2024)