Benchmarking Autonomous Agents against Temporal, Spatial, and Semantic Evasions

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ma, Jianan, Du, Xiaohu, Lin, Ruixiao, Bian, Yaoxiang, Chen, Jialuo, Wang, Jingyi, Yang, Xiaofang, Cui, Shiwen, Meng, Changhua, Deng, Xinhao, Wang, Zhen
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916035970465792
author Ma, Jianan
Du, Xiaohu
Lin, Ruixiao
Bian, Yaoxiang
Chen, Jialuo
Wang, Jingyi
Yang, Xiaofang
Cui, Shiwen
Meng, Changhua
Deng, Xinhao
Wang, Zhen
author_facet Ma, Jianan
Du, Xiaohu
Lin, Ruixiao
Bian, Yaoxiang
Chen, Jialuo
Wang, Jingyi
Yang, Xiaofang
Cui, Shiwen
Meng, Changhua
Deng, Xinhao
Wang, Zhen
contents As autonomous agents (e.g., OpenClaw) increasingly operate with deep system-level privileges to execute complex tasks, they introduce severe, unmitigated security risks. Current vulnerability analyses overwhelmingly focus on single-turn, stateless behaviors, overlooking the expanded attack surface inherent in stateful, multi-turn interactions and dynamic tool invocations. In this paper, we propose a novel, multi-dimensional evasion framework targeting LLM-based agent systems. We introduce three stealthy attack vectors: (1) Temporal evasion, which fragments malicious payloads across sequential interaction turns; (2) Spatial evasion, which conceals payloads within complex external artifacts that evade standard LLM parsing mechanisms; and (3) Semantic evasion, which obscures malicious intents beneath benign contextual noise. To systematically quantify these threats, we construct A3S-Bench, a comprehensive benchmark comprising 2,254 real-world agent execution trajectories. Evaluating a standard agent framework separately integrated with 10 mainstream LLM backbones against 20 practical threat scenarios, we demonstrate that our evasion framework elevates the average risk trigger rate from a 28.3\% baseline to 52.6\%. These findings reveal systemic, architecture-level vulnerabilities in current autonomous agent systems that existing defenses fail to address, highlighting an urgent need for defense mechanisms tailored to the unique threats.
format Preprint
id arxiv_https___arxiv_org_abs_2605_22321
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Benchmarking Autonomous Agents against Temporal, Spatial, and Semantic Evasions
Ma, Jianan
Du, Xiaohu
Lin, Ruixiao
Bian, Yaoxiang
Chen, Jialuo
Wang, Jingyi
Yang, Xiaofang
Cui, Shiwen
Meng, Changhua
Deng, Xinhao
Wang, Zhen
Cryptography and Security
Artificial Intelligence
Software Engineering
K.6.5, I.2.6
As autonomous agents (e.g., OpenClaw) increasingly operate with deep system-level privileges to execute complex tasks, they introduce severe, unmitigated security risks. Current vulnerability analyses overwhelmingly focus on single-turn, stateless behaviors, overlooking the expanded attack surface inherent in stateful, multi-turn interactions and dynamic tool invocations. In this paper, we propose a novel, multi-dimensional evasion framework targeting LLM-based agent systems. We introduce three stealthy attack vectors: (1) Temporal evasion, which fragments malicious payloads across sequential interaction turns; (2) Spatial evasion, which conceals payloads within complex external artifacts that evade standard LLM parsing mechanisms; and (3) Semantic evasion, which obscures malicious intents beneath benign contextual noise. To systematically quantify these threats, we construct A3S-Bench, a comprehensive benchmark comprising 2,254 real-world agent execution trajectories. Evaluating a standard agent framework separately integrated with 10 mainstream LLM backbones against 20 practical threat scenarios, we demonstrate that our evasion framework elevates the average risk trigger rate from a 28.3\% baseline to 52.6\%. These findings reveal systemic, architecture-level vulnerabilities in current autonomous agent systems that existing defenses fail to address, highlighting an urgent need for defense mechanisms tailored to the unique threats.
title Benchmarking Autonomous Agents against Temporal, Spatial, and Semantic Evasions
topic Cryptography and Security
Artificial Intelligence
Software Engineering
K.6.5, I.2.6
url https://arxiv.org/abs/2605.22321