From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows

Published
Source
arXiv
Paper number
069
Field
Security / Agents
arXiv ID
2506.23260

Key points

  • The rapid spread of LLM-based AI agents and their complex ecosystems lacks standardized, robust security practices, leading to widespread vulnerabilities.
  • Current integrations often rely on ad hoc authentication and weak verification mechanisms, making them highly vulnerable to many forms of exploitation.
  • Existing security research on LLM agents is fragmented and has not provided a unified end-to-end framework that covers threats across the full communication stack, from host-to-tool interactions to agent-to-agent interactions.
  • A unified end-to-end threat model was developed that systematically analyzes security risks across the entire LLM agent ecosystem, including host-to-tool and agent-to-agent communication.
  • More than 30 different attack techniques were classified into four major areas: input manipulation, model corruption, system and privacy attacks, and protocol vulnerabilities.
  • Rigorous mathematical formulations were provided for each threat category, explicitly defining attacker capabilities, goals, and affected layers to enable systematic analysis.

Paper links

External research summaries. These are not HDATF publications or measured product results.

Read original (opens in a new tab)