כתבה
arXiv cs.AI ·
Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents
תקציר מקורי באנגליתarXiv:2605.02187v2 Announce Type: replace-cross Abstract: LLM agents convert model outputs into consequential actions, including communications, code changes, and financial transactions. Developers often trust evidence such as test results and execution logs. We identify a response path integrity gap in Bring Your Own Key configurations used by roughly 88 percent of mainstream agents. Because traffic passes through a user-authorized relay, the relay can modify plaintext LLM responses after alignment but before execution without breaking encryption. A minimal attack rewrites one execution bearing field and regenerates the remaining response using the user key while preserving the model style. Experiments reveal false green verification, where malicious code modifications pass public tests w
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית