Tool-using large language model (LLM) agents are vulnerable to indirect prompt injection (IPI), in which malicious instructions embedded in external observations manipulate subsequent agent decisions and actions. Most existing adaptive attacks rely on repeatedly querying and refining against the target agent, whereas r...
Sihan Hou, Xin-Meng Hou, Zhi-Jun Zhang et al.· 0 citations
This work proposes a trajectory-aware subset selection approach that replaces random sampling with deterministic selection based on trajectory embeddings, and shows that a 10% trajectory-aware subset keeps the median estimation error below 5% while cutting token cost by roughly 90%.
Mahmoud Ayyad, Ze-Hao Wang, Ji-Ho Shin et al.· 0 citations
Ledger is proposed, a deterministic runtime layer that distills an agent's completed interactions into an explicit execution state: what has been observed, what has been modified, and what has been attempted, in an online execution ledger and applies it at two boundaries of every step.
Zehao Wang, Yisen Xu, Cheng-Lin Li et al.· 2 citations
ECLoop is presented, an execution layer that interposes between the agent and the repository to enforce evidence-conditioned execution and shows that each of ECLoop's three operations contributes distinct value and that structured evidence conditions outperform an equivalent natural-language summary.
Yisen Xu, Chenglin Li, Zehao Wang et al.· arXiv.org· 2 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.