PulseAugur
中
实时 08:11:37
English(EN) Context-Fractured Decomposition Attacks on Tool-Using LLM Agents: Exploiting Artifact Provenance Gaps

新的越狱攻击利用LLM代理工件漏洞

研究人员开发了一种名为上下文破碎分解(CFD)的新型越狱技术,该技术针对使用工具的LLM代理。该方法利用了工件溯源跟踪中的漏洞,其中中间的、看似良性的操作可能会在之后触发有害行为。通过利用这些工件的延迟组合,CFD将越狱成功率提高了多达28.3个百分点,即使面对强大的防御措施。 AI

影响 这项研究突显了LLM代理的一个关键漏洞,可能需要新的工件溯源和跨上下文推理安全范式。

排序理由 该集群包含一篇详细介绍针对LLM代理的新攻击方法的学术论文。

在 Hugging Face Daily Papers 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

新的越狱攻击利用LLM代理工件漏洞

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Research
该集群包含一篇详细介绍针对LLM代理的新攻击方法的学术论文。
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
paper, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
115 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [2]

  1. arXiv cs.AI TIER_1 English(EN) · Xiaofeng Lin, Yukai Yang, Daniel Guo, Sahil Arun Nale, Charles Fleming, Guang Cheng ·

    针对使用工具的LLM代理的上下文破碎分解攻击:利用工件溯源的差距

    arXiv:2606.09084v1 Announce Type: cross Abstract: Tool-using LLM agents interact with the world through actions that persist state in artifacts (e.g., workspace files or logs). Consequently, jailbreak defenses must reason about cross-step composition rather than isolated text. Ye…

  2. Hugging Face Daily Papers TIER_1 English(EN) ·

    针对使用工具的大型语言模型代理的上下文破碎分解攻击:利用工件溯源差距

    Tool-using LLM agents interact with the world through actions that persist state in artifacts (e.g., workspace files or logs). Consequently, jailbreak defenses must reason about cross-step composition rather than isolated text. Yet most existing attacks and defenses, including ``…