arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33910cs.AI

当同意超越上下文:长寿智能体中的残余权限重放

When Consent Outlives Context: Residual Authority Replay in Long-Lived Agents

Zhihao Zhang, Chao Wang, Rujia Li, Qingze Wang, Xiaoyan Sun, Jun Dai

首次发表
浏览论文内容

中文总结 AI 辅助

本研究揭示长寿LLM智能体中授权可超越原始上下文形成残余权限,通过纵向攻击证明该漏洞显著提升提示注入和上下文重绑定攻击成功率,暴露持久授权与用户同意上下文性之间的根本矛盾。

中文摘要 AI 辅助

LLM智能体越来越依赖用户批准来在运行时授权安全敏感操作。此类批准是在特定任务和执行上下文中授予的。在长寿智能体中,授权决策可能需要跨任务或会话持续有效。我们发现,这种持续性可能超越最初证明批准合理的上下文,从而产生无需重新同意即可重用的残余权限。我们通过一种纵向攻击暴露了这一故障模式,该攻击从目标安全敏感操作开始,识别执行该操作所需的权限,诱导良性交互以合法获得该权限,并在对抗性执行期间稍后重放残余权限。在受控和实时环境中,我们证明了残余权限重放在实际中发生,并显著提高了提示注入和上下文重绑定攻击的成功率。我们使用生产派生的授权语义,评估了六个LLM家族的508个AgentDojo攻击案例。与全新授权状态相比,残余权限使攻击成功率(ASR)最多提高35.1个百分点。在针对三个真实生产编码智能体的55个Terminal-Bench案例的实时上下文重绑定攻击中,残余权限重放使ASR平均提高24.9个百分点。这些发现暴露了持久授权与LLM智能体中用户同意的上下文性质之间的根本不匹配。

英文摘要

LLM agents increasingly rely on user approval to authorize security-sensitive actions at runtime. Such approvals are granted within a specific task and execution context. In long-lived agents, authorization decisions may need to persist across tasks or sessions. We find that this continuity can outlive the context that originally justified the approval, creating residual authority reusable without renewed consent. We expose this failure mode through a longitudinal attack that starts from a target security-sensitive action, identifies the authority required to execute it, induces benign interactions that legitimately obtain that authority, and later replays the residual authority during adversarial execution. Across controlled and live settings, we demonstrate that residual-authority replay arises in practice and substantially increases the success of prompt-injection and context-rebinding attacks. We evaluate 508 AgentDojo attack cases across six LLM families using production-derived authorization semantics. With residual authority, attack success rate (ASR) increases by up to 35.1 percentage points compared with a fresh authorization state. In live context-rebinding attacks on 55 Terminal-Bench cases across three real-world production coding agents, residual-authority replay increases ASR by 24.9 percentage points on average. These findings expose a fundamental mismatch between persistent authorization and the contextual nature of user consent in long-lived LLM agents.

发表机构

  • Worcester Polytechnic Institute(伍斯特理工学院)
  • Tsinghua University(清华大学)

机构由 AI 辅助整理,请以论文原文为准。

↑