From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
- Published
- Source
- arXiv
- Paper number
- 069
- Field
- Security / Agents
- arXiv ID
- 2506.23260
Key points
- The rapid spread of LLM-based AI agents and their complex ecosystems lacks standardized, robust security practices, leading to widespread vulnerabilities.
- Current integrations often rely on ad hoc authentication and weak verification mechanisms, making them highly vulnerable to many forms of exploitation.
- Existing security research on LLM agents is fragmented and has not provided a unified end-to-end framework that covers threats across the full communication stack, from host-to-tool interactions to agent-to-agent interactions.
- A unified end-to-end threat model was developed that systematically analyzes security risks across the entire LLM agent ecosystem, including host-to-tool and agent-to-agent communication.
- More than 30 different attack techniques were classified into four major areas: input manipulation, model corruption, system and privacy attacks, and protocol vulnerabilities.
- Rigorous mathematical formulations were provided for each threat category, explicitly defining attacker capabilities, goals, and affected layers to enable systematic analysis.
Paper links
External research summaries. These are not HDATF publications or measured product results.