PulseAugur
实时 09:11:02
English(EN) Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS

新研究揭示LLM代理的内存中毒攻击

两篇新研究论文MemMorph和Evo-Attacker详细介绍了通过利用大型语言模型(LLM)代理的内存系统进行攻击的新方法。MemMorph通过精心设计的记录来毒害代理的长期记忆,以微妙地影响工具选择,用少量数据即可实现高成功率。Evo-Attacker使用内存增强强化学习来动态演化针对基于LLM的多代理系统(LLM-MAS)中长时域工具操纵的攻击策略。两项研究都强调了LLM代理内存模块的脆弱性,并强调了对健壮的内存级安全防护措施的迫切需求。 AI

影响 这些研究揭示了LLM代理内存系统的关键漏洞,需要开发新的安全措施来防止恶意工具劫持。

排序理由 两篇在arXiv上发表的学术论文,详细介绍了针对LLM代理的新型攻击向量。

在 arXiv cs.MA (Multiagent) 阅读 →

AI 生成摘要 · Google Gemini · 来自 3 个来源。 我们如何撰写摘要 →

新研究揭示LLM代理的内存中毒攻击

报道来源 [3]

  1. arXiv cs.AI TIER_1 English(EN) · Xuanye Zhang, Yongsen Zheng, Zhuqin Xu, Kaiyu Zhou, Bowen Shen, Haoran Ou, Tianwei Zhang, Kwok-Yan Lam ·

    MemMorph:通过内存投毒在 LLM 代理中进行工具劫持

    arXiv:2605.26154v1 Announce Type: cross Abstract: LLM-driven agents are capable of selecting external tools to complete users' tasks. However, attackers could compromise such process, steering agents toward inappropriate/wrong tools and enabling malicious actions. Most existing a…

  2. arXiv cs.AI TIER_1 English(EN) · Bingyu Yan, Xiaoming Zhang, Jinyu Hou, Chaozhuo Li, Ziyi Zhou, Yiming Hei, Litian Zhang ·

    Evo-Attacker:用于 LLM-MAS 长期工具攻击的记忆增强强化学习

    arXiv:2605.25389v1 Announce Type: cross Abstract: While Large Language Model-based Multi-Agent Systems (LLM-MAS) demonstrate remarkable capabilities in solving complex tasks by orchestrating specialized agents and external tools, the implicit trust in tool outputs creates a criti…

  3. arXiv cs.MA (Multiagent) TIER_1 English(EN) · Litian Zhang ·

    Evo-Attacker:用于长时域工具攻击LLM-MAS的内存增强强化学习

    While Large Language Model-based Multi-Agent Systems (LLM-MAS) demonstrate remarkable capabilities in solving complex tasks by orchestrating specialized agents and external tools, the implicit trust in tool outputs creates a critical attack surface. Existing tool attacks are limi…