arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

你的智能体上下文中有什么?针对AI智能体管控工具的上下文权限提升攻击

What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness

Zichuan Li, Jian Cui, Ashley Chen, Xiaojing Liao, Luyi Xing

arXiv 2609.01222首次发表:更新:

发表机构

University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对现实中AI智能体管控工具的上下文组装设计,首次系统分析出M-CPE和X-CPE两类新型上下文权限提升攻击,并在12款工具上验证其可导致智能体被完全控制等严重安全后果。

AI 中文摘要

现实中备受关注的AI智能体管控工具(agent harness)常依赖厂商专有或不透明的上下文组装设计,导致组装后的上下文来源和底层逻辑难以理解,相关安全风险也基本未被探索。本文首次对现实中AI智能体管控工具的上下文组装设计进行系统分析,研究并揭示了智能体管控工具如何从不同来源收集和组装上下文,以及这些设计引发的一系列实用攻击向量。我们的分析发现了现实管控工具上下文组装中的两类新型攻击:(1)消息角色上下文权限提升(MessageRole Context Privilege Escalation,M-CPE),指攻击者控制的、来自低权限上下文的内容被纳入高权限消息角色;(2)跨范围上下文权限提升(Cross-Scope Context Privilege Escalation,X-CPE),指攻击者控制的内容在其被引入的上下文之外持续存在。我们对包括Claude Code和Codex在内的12种现实智能体管控工具开展了针对CPE攻击的系统安全分析,产生的后果包括完全控制智能体、远程代码执行、拒绝服务、操纵工具或技能调用等。

英文摘要

Real-world, high-profile AI agent harnesses often rely on vendor-proprietary or opaque designs for context assembly, leaving the sources and underlying logic of assembled context poorly understood and the resulting security risks largely unexplored. In this paper, we present the first systematic analysis of context assembly designs in real-world AI agent harnesses. We study and uncover how an agent harness is designed to collect and assemble context from diverse sources, and identify a set of practical attack vectors arising from these designs. Our analysis brings to light two novel categories of attacks in the context assembly of real-world harnesses: (1) MessageRole Context Privilege Escalation (M-CPE), which occurs when attacker-controlled content originating from a low-privileged context is incorporated into a higher-privileged message role. (2) Cross-Scope Context Privilege Escalation (X-CPE), which occurs when attacker-controlled content persists beyond the context in which it was introduced. We performed a systemic security analysis of the CPE attacks against 12 real-world agent harnesses, including Claude Code and Codex. The resulting consequences include full agent compromise, remote code execution, denial of service, and manipulated tool or skill invocations, etc.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑