paper-with-me

홈 › Papers

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

2025-02-12 · Ang Li, Yin Zhou, Vethavikashini Chithrra Raghuram, Tom Goldstein, Micah Goldblum

A high volume of recent ML security literature focuses on attacks against aligned large language models (LLMs). These attacks may extract private information or coerce the model into producing harmful outputs. In real-world deployments, LLMs are often part of a larger agentic pipeline including memory systems, retrieval, web access, and API calling. Such additional components introduce vulnerabilities that make these LLM-powered agents much easier to attack than isolated LLMs, yet relatively little work focuses on the security of LLM agents. In this paper, we analyze security and privacy vulnerabilities that are unique to LLM agents. We first provide a taxonomy of attacks categorized by threat actors, objectives, entry points, attacker observability, attack strategies, and inherent vulnerabilities of agent pipelines. We then conduct a series of illustrative attacks on popular open-source and commercial agents, demonstrating the immediate practical implications of their vulnerabilities. Notably, our attacks are trivial to implement and require no understanding of machine learning.

📄 PDF Abstract BibTeX arXiv:2502.08586

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Mobile GUI Agents under Real-world Threats: Are We There Yet?

2025-07-06 · Guohong Liu, Jialei Ye, Jiacheng Liu, Yuanchun Li 외 arxiv

Recent years have witnessed a rapid development of mobile GUI agents powered by large language models (LLMs), which can autonomously execute diverse device-control tasks based on natural language instructions. The increa…

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments

2026-05-11 · Chiyu Zhang, Huiqin Yang, Bendong Jiang, Xiaolei Zhang 외 arxiv

The rapid proliferation of LLM-based autonomous agents in real operating system environments introduces a new category of safety risk beyond content safety: behavior jailbreak, where an adversary induces an agent to exec…

It Lied to a Doctor to Buy Poison Ingredients: Quantifying Real-World Misuse of Phone-use Agents

2026-06-26 · Yiming Sun, Chen Chen, Zifan Zhou, Mi Zhang arxiv

Phone-use Agents can execute complex tasks end to end across real mobile applications. By operating a real device on the user's behalf, they reach far more functionalities than CLI agents, which amplifies the real-world …

BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents

2024-06-05 · Yifei Wang, Dizhan Xue, Shengjie Zhang, Shengsheng Qian

With the prosperity of large language models (LLMs), powerful LLM-based intelligent agents have been developed to provide customized services with a set of user-defined tools. State-of-the-art methods for constructing LL…

Quantifying CBRN Risk in Frontier Models

2025-10-24 · Divyanshu Kumar, Nitin Aravind Birur, Tanay Baswa, Sahil Agarwal 외 arxiv

Frontier Large Language Models (LLMs) pose unprecedented dual-use risks through the potential proliferation of chemical, biological, radiological, and nuclear (CBRN) weapons knowledge. We present the first comprehensive …

Prompt Engineering