paper-with-me

Papers

VATS: Exploiting Implicit Authority in Error-Path Injection via Systematic Mutation

2026-06-06 · Harshil Patel, Kunal Pai arxiv

As the Model Context Protocol (MCP) standardizes tool-calling for autonomous agents, it introduces a critical, unexamined attack surface: the error-handling loop. We hypothesize that tool error messages possess implicit authority, triggering corrective reasoning modes that bypass standard safety heuristics. We introduce VATS (Vulnerability Analysis of Tool Streams), a mutation-driven framework that systematically evolves adversarial payloads across seven structural and linguistic dimensions. Our evaluation across four frontier models, Gemini 3.1 Pro, GPT-5.5, GLM-5.1, and Qwen3-Coder, demonstrates that error-path injection triples the success rate of standard indirect prompt injection (IPI), achieving up to 100% compliance in controlled evaluations. We isolate structural positioning (sandwiching instructions within error context) as the most effective exploit vector across all tested models. While we find that production framework guardrails can mitigate these vulnerabilities, the inherent susceptibility of the model layer poses a systemic risk to bespoke agentic workflows.

📄 PDF Abstract BibTeX arXiv:2606.07992

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

DeepVATS: Deep Visual Analytics for Time Series

2023-02-08 · Victor Rodriguez-Fernandez, David Montalvo, Francesco Piccialli, Grzegorz J. Nalepa 외

The field of Deep Visual Analytics (DVA) has recently arisen from the idea of developing Visual Interactive Systems supported by deep learning, in order to provide them with large-scale data processing capabilities and t…

Time SeriesTime Series Analysis

When Memory Becomes Authority: Benchmarking Authority Collapse at the Memory Consolidation Boundary

2026-08-03 · Qiuyang Zhan, Rui Zhang, Sheng Guo, Lepeng Zhao 외 arxiv

Persistent memory allows (self-evolving) LLM agents to adapt across tasks by consolidating heterogeneous interaction histories into reusable facts, preferences, observations, and rules. Yet consolidation also imposes an …

Authority Inversion in LLM-Mediated Ubiquitous Systems: When Models Trust Users Over Sensors

2026-04-28 · Long Zhang, Zi-bo Qin, Wei-neng Chen arxiv

Large language models (LLMs) increasingly fuse heterogeneous inputs in ubiquitous systems. Yet, how LLMs implicitly allocate authority when sensor measurements and user claims conflict remains unexamined, raising critica…

Three-dimensional Nonlinear Path-following Guidance with Bounded Input Constraints

2024-09-13 · Saurabh Kumar, Shashi Ranjan Kumar, Abhinav Sinha

In this paper, we consider the tracking of arbitrary curvilinear geometric paths in three-dimensional output spaces of unmanned aerial vehicles (UAVs) without pre-specified timing requirements, commonly referred to as pa…

Legible Shared Autonomy: Implicit Communication of Robot Belief through Motion

2026-06-29 · Jinwei Liu, Pengfei Li, Shaofeng Chen, Tao Wang 외 arxiv

Shared autonomy systems combine user input with autonomous assistance to help users with motor impairments control robot arms to perform everyday manipulation tasks, by inferring user goals and providing appropriate guid…