AgentXploit is a two‑role auditing system that separates repository‑level attack‑path discovery from runtime exploitation for AI agents. The Analyzer Agent traces attacker‑controlled inputs to sensitive operations and records candidate attack paths, while the Exploiter Agent turns these paths into concrete attacks and refines them using runtime feedback. The system is evaluated on AgentXploit‑Bench, a benchmark of 72 reproducible vulnerabilities across 12 open‑source AI‑agent systems, achieving 59.3% end‑to‑end success compared to 38.4% for Codex, and 79.2% attack success on AgentDojo versus 52.7% for AgentVigil.
By Weida Liang, Shi Qiu, Zhun Wang, Simon Sure, Xiaoyuan Liu, Tianneng Shi, Zhaorun Chen, Wenbo Guo, Dawn Song
arXiv:2604. 05485v2 Announce Type: replace Abstract: LLM agents call tools, query databases, delegate tasks, and trigger external side effects.
By Yi Nian, Aojie Yuan, Haiyue Zhang, Jiate Li, Li Li, Xiyang Hu, Hua Wei, Xiongye Xiao, Chaowei Xiao, Yue Zhao
arXiv:2606. 09692v1 Announce Type: cross Abstract: Delegation-scoped execution is not identifiable from standard observables: audit logs and execution traces can be identical under multiple incompatible delegation assignments.
By Abhinav Mishra, Kumar Sharad
arXiv:2609.14987v1 Announce Type: cross
Abstract: Large language model (LLM) agents interact with external environments through tool invocation, but tool outputs can also expose them to indirect prom...
By Bingzheng Wang, Xiaoyan Gu, Wentao Wang, Xingyou Yang, Hongcheng Li, Rong Yin
arXiv:2608. 07346v1 Announce Type: new Abstract: With the rapid advancement of large language models (LLMs), harnesses have become essential infrastructure for deploying agents across a wide range of domains.
By Haoning Wang, Mingxun Zhang, Chenyue Yu, Yingjun Shang, Xia Hu, Guanchu Wang, Na Zou
The paper investigates why large language model (LLM) agents fail in the Emergence World simulation, noting that agents committed crimes, starved, and enforced conformity without external attackers. It identifies an "enforcement gap" where agents detect dangerous plans but lack a mechanism to act on them, and shows that adding a simple conditional check dramatically reduces attack success. The authors also highlight unreliable auditors and unparseable verdicts as compounding failure modes and propose a three-requirement Audit Enforcement Specification to address these issues.
By Yuhang Wang
The paper introduces a typed snapshot‑settlement contract for auditing concurrent actions in large language model agent environments. It evaluates three properties—order sensitivity, useful progress, and replay consistency—across five settlement policies, using 28,800 exhaustive permutation trials and 2,160 scripted multistep episodes. Results show that joint policies are spatially order‑invariant with fixed priorities, but conservative rejection only completes 31.25% of agents in a six‑agent doorway task compared to 90.28% for random tickets, while a full‑state journal audit successfully replays 156 checkpoints and rejects 1,332 constructed corruptions.
By Haotian Chen, Bowen Ye, Yuning Zhang, Jingkun Yu
MAS-Shield is a defense framework for Large Language Model–based Multi-Agent Systems that uses a coarse‑to‑fine filtering pipeline. It first selects critical agents, then applies lightweight auditing to most cases, and finally escalates only suspicious signals to a heavyweight committee. Experiments show a 92.5% recovery rate against adversarial attacks and a latency reduction of over 70% compared to existing methods.
By Kaixiang Wang, Zhaojiacheng Zhou, Bunyod Suvonov, Jiong Lou, Zihan Wang, Yuxiang Zheng, Yidan Lin, Wutong Zhang, Xianghan Kong, Chentao Wu, Jie Li
arXiv:2609.33676v2 Announce Type: replace
Abstract: LLM agents increasingly take consequential actions through interactions with users, policies, and external tools. Auditing these agents requires au...
By Yifan Liu, Praveen Venkateswaran, Abdulhamid Adebayo, Dong Wang
arXiv:2608. 07346v2 Announce Type: replace Abstract: With the rapid advancement of large language models (LLMs), harnesses have become essential infrastructure for deploying agents across a wide range of domains.
By Haoning Wang, Mingxun Zhang, Chenyue Yu, Yingjun Shang, Xia Hu, Guanchu Wang, Na Zou
LEDGER is a tracing and review system for large language model agents that constructs layered trace graphs from observed sessions. It groups raw trace records into Evidence Nodes and Workflow Nodes, anchors artifacts as evidence, and adds typed semantic edges linking claims to supporting actions, artifacts, and checks. The resulting traces reveal workflow decisions, artifact lineage, repair steps, validation coverage, and claim‑support paths for evidence‑centered audit.
By Daehong Kim, Haichao Miao, Shusen Liu
arXiv:2608.01772v2 Announce Type: replace
Abstract: LLM agents increasingly run policy-bound enterprise workflows, where they must apply rules consistently and stay auditable. Deploying such an agent...
By Ruoqi Shu, Chen Dan, Xuhui Wang, Tianhua Xu, Mengxi Luo, Yanming Mai, Bo Wan