כתבה
arXiv cs.AI ·
שרשרת כישורים לחטיפת סוכנים LLM
Chaining Skills to Hijack LLM Agents
APEX בונה שרשראות כישורים יריבות לסוכנים LLM. המחקר מראה כי 74.2% מהניסיונות הצליחו. GPT-5.4 הצליחה ב-84.3% מהניסיונות.
תקציר מקורי באנגליתarXiv:2610.01564v1 Announce Type: cross Abstract: LLM agents use skills to improve performance on specialized tasks. To complete a user request, an agent may invoke several skills in sequence, allowing information produced under one skill to guide the next. Because skills may come from open-source repositories, this handoff can also carry attacker-controlled claims into later decisions. In this paper, we introduce APEX, which constructs and refines adversarial skill chains tailored to a user task and an attacker-selected action. The key insight is that an agent-written record of genuine task progress can carry a false claim of user approval across skills: an upstream skill induces the agent to create the record, and a downstream skill uses it to direct the attacker-selected action. Across
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית