arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

收敛式绕路劫持:基于技能的大语言模型智能体中的任务保留型资源放大

Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents

Junliang Liu, Ruoyu Li, Wenxin Tang, Jingyu Xiao, Zhenyu Liu, Jingheng Xu, Laizhong Cui

arXiv 2608.12273首次发表:更新:

发表机构

Shenzhen University; The Chinese University of Hong Kong; The Chinese University of Hong Kong, Shenzhen(深圳大学; 香港中文大学; 香港中文大学(深圳))

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出收敛式绕路劫持攻击,耦合LLM智能体技能选择与规划阶段,可放大任务资源消耗,在DeepSeek-V4-Pro上80.02%的任务会被选中攻击者控制的协调器,任务完成率不变但成本显著提升。

AI 中文摘要

大语言模型(LLM)智能体越来越依赖第三方技能,使用自然语言描述进行技能选择,使用指令体进行规划。这种渐进式披露设计向不可信的发布者暴露了两个连续的控制点:静态技能可能会将原本正确的任务引导至不必要的高成本轨迹。现有研究大多分别探讨选择操纵、恶意技能指令和工具链资源放大,而它们的端到端组合尚不明确。我们提出了收敛式绕路劫持(Convergent Detour Hijacking,CDH),一种纯文本、与运行时无关的攻击,它将这些阶段耦合起来。在共享语义掩护下,描述部分在选择阶段建立相关性,而对齐的指令体则利用该理由在规划阶段构建合理的依赖关系。CDH会吸引攻击者控制的协调器以及合法技能,将不必要的良性技能招募到有限的绕路中,随后重新进入原始路径以保留任务完成。我们在多个LLM后端和491个保留任务上,针对单任务和多轮条件进行评估。在DeepSeek-V4-Pro上,80.02%的任务被选中了攻击者控制的协调器;在协调器命中且完成任务的运行中,令牌消耗和端到端执行时间分别增加了66.91%和92.45%,而总任务完成率仍保持相当。因此,正确的结果并不能保证轨迹完整性或成本安全性。

英文摘要

LLM agents increasingly rely on third-party skills, using natural-language descriptions for selection and instruction bodies for planning. This progressive-disclosure design exposes two sequential control points to untrusted publishers: a static skill may steer an otherwise correct task onto an unnecessarily costly trajectory. Prior work studies selection manipulation, malicious skill instructions, and tool-chain resource amplification largely separately, leaving their end-to-end composition unclear. We introduce Convergent Detour Hijacking (CDH), a text-only, runtime-independent attack that couples these stages. Under shared semantic cover, a description establishes relevance during selection, while an aligned body reuses that rationale to fabricate plausible dependencies during planning. CDH attracts an attacker-controlled coordinator alongside legitimate skills, recruits unnecessary benign skills into a bounded detour, and then re-enters the original route to preserve task completion. We evaluate it across multiple LLM backends and 491 held-out tasks under single-task and multi-turn conditions. On DeepSeek-V4-Pro, the matched coordinator is selected in 80.02% of tasks; among coordinator-hit runs that complete tasks, token consumption and end-to-end execution time increase by 66.91% and 92.45%, respectively, while aggregate task completion remains comparable. Thus, correct outcomes do not guarantee trajectory integrity or cost safety.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑