Skip to content

Agentic Threats

Tool misuse, autonomous harm, and agent-specific attack vectors

Resources
380
Page
7/8

Newest first · 1 reviewed on this page

Search instead
paper2026ComputersUnreviewed

Evaluating Indirect Prompt Injection Defenses in Tool-Using LLM Agents: Security, Utility, and Replication

Adil Khan, Khaled AlKhanbashi, Azza Mohamed

Large language model (LLM) agents that retrieve external content and use tools are vulnerable to indirect prompt injection, in which untrusted content contains instructions intended to influence agent behavior. We evaluated four defenses and an undefended control across GPT-5.4,…

paper2026InformationUnreviewed

Agentic AI Security in Industry 5.0: Emerging Threats, Forensic Readiness, and Trustworthy Human–Agent Collaboration

Maurice E. Dawson, A. B. Ben Ayed, Samson Quaye

Industry 5.0 places autonomous agents inside its human–agent collaborative loop, resting its human-centricity pillar on an assumption of trustworthy collaboration that has not been examined critically. Agentic artificial intelligence has moved from research demonstration to…

paper2026ElectronicsUnreviewed

Securing the Prompt Pipeline: A Systematic Review of Defense Mechanisms Against Prompt-Based Attacks in LLM Agents

Sana Mourad, E. E. Abdallah, Mohammad Ababneh

Current language model deployments face growing security challenges from prompt-based attacks, including jailbreaks, direct and indirect prompt injection, and instruction hijacking, which often evade traditional rule-based safeguards. As these models are increasingly integrated…

paper2026Unreviewed

BioFirewall: A genome-writing-native governance layer for design-stage biosecurity screening of agentic AI

Anees Ahmed Mahaboob Ali, R. Delhibabu, Everette Jacob Remington Nelson

Background. Artificial-intelligence design tools now plan genome-scale edits, and agentic systems execute those plans with progressively less human oversight. Biosecurity controls are limited to two points: refusal guardrails at the foundation model and sequence-identity…

paper2026Artificial Intelligence and ApplicationsUnreviewed

CAPS: Compositional Attack Path Scoring for LLM Deployment Stacks

Quang-Vinh Dang, Hoang-Viet Vu, Ngoc-Son-An Nguyen +2

Evaluating the security posture of large language model (LLM) deployment stacks is a critical challenge in modern AI security. Traditional vulnerability management frameworks—such as the Common Vulnerability Scoring System (CVSS) and component-level checklists—assume that…

Agentic ThreatsOpen access
paper2026Unreviewed

Backdoor Decontamination Dynamics in LLM Agents

Gabriel Huang, Abhay Puri, L'eo Boisvert +4

Open-weight LLM agents are vulnerable to backdoors installed during fine-tuning, which may be undetectable if the trigger conditions are never met during testing. Assuming defenders do not know the existing trigger, they cannot unlearn it directly. One decontamination strategy…

paper2026Unreviewed

Agentic Harnesses: LLM-Driven Verification Layers for Robot Autonomy

Rohan Bhagra, Mahantesh Halapannavar, Uddhav Bhattarai

Advances in advanced artificial intelligence tools have sparked research in robot autonomy, but the development of such systems has largely focused on execution rather than verifying the feasibility actions planning models propose. Like general-purpose LLMs, robotics planning…

paper2026Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2Unreviewed

Shifting the Unit of Safety: From Model to System in the Generative and Agentic Era

Sakshi Jain

For a decade, responsible AI at internet scale rested on a reassuring assumption: that risk lives primarily in a model, it is a unit you can isolate, and that privacy, fairness and safety is therefore something you certify at model level, before launch. At LinkedIn, where AI…

paper2026International Conference on Cyber Security And Protection Of Digital ServicesUnreviewed

Securing agentic AI workflows: A defence-in-depth framework for autonomous systems

Sushma Mahadevaswamy

The rapid enterprise adoption of agentic artificial intelligence (AI) has introduced a category of security risk that existing cyber security frameworks were not designed to address. With 78 per cent of Fortune 500 companies projected to deploy agentic AI by 2026 and the global…

paper2026International Journal of Scientific Research in Computer Science Engineering and Information TechnologyUnreviewed

SAFE-HealCloud: Safety-Aware, Agentic Self-Healing for Cloud Infrastructure

Prudvi Saisaran Ponduru, Pavani Priya Vyshnavi Nandanavanam, S. Ponduru

Cloud infrastructure failures are increasingly difficult to detect, diagnose, and remediate because production environments combine microservices, Kubernetes control loops, service meshes, serverless workloads, infrastructure-as-code, continuous delivery, and heterogeneous…

paper2026Unreviewed

Prompt Injection Attacks Against Clinical LLM Agents Accessing Electronic Health Records: A Survey, Threat Model, Benchmark Specification, and Layered Defense Synthesis

Divya Pandey, Shivani Manchanda, Gangesh Pathak +1

Clinical large language model (LLM) agents are entering production hospital deployments, where they read longitudinal electronic health records (EHRs), retrieve evidence from clinical knowledge bases, and assist with summarization, dosing, triage, and guideline-based decisions.…

paper2026Stout in Computer Science and Technology StudiesUnreviewed

Continual Red-Teaming and Guardrail Distillation for Tool-Using LLM Agents: Prompt-Injection Resistance with Utility Preservation

Wesley Gao

Tool-using language-model agents can convert indirect prompt injection into consequential actions, making guardrail quality a joint security, utility, and efficiency problem. This study evaluates a ReAct-style control, native tool filtering, deterministic self-verification, a…

paper2025AI OpenUnreviewed

TRiSM for Agentic AI: A Review of Trust, Risk, and Security Management in LLM-based Agentic Multi-Agent Systems

Shaina Raza, Ranjan Sapkota, Manoj Karkee +1

Agentic AI systems, built upon large language models (LLMs) and deployed in multi-agent configurations, are redefining intelligence, autonomy, collaboration, and decision-making across enterprise and societal domains. This review presents a structured analysis of Trust, Risk,…

paper2025AlgorithmsUnreviewed

A Research Landscape of Agentic AI and Large Language Models: Applications, Challenges and Future Directions

Domenico Ursino, Gianluca Bonifazi, Enrico Corradini +5

Agentic AI and Large Language Models (LLMs) are transforming how language is understood and generated while reshaping decision-making, automation, and research practices. LLMs provide underlying reasoning capabilities, and Agentic AI systems use them to perform tasks through…

Agentic ThreatsOpen access47 cit.
paper2025Conference on Empirical Methods in Natural Language ProcessingUnreviewed

IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents

Hengyu An, Jinghuai Zhang, Tianyu Du +4

Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks. However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool…

paper2025Network and Distributed System Security SymposiumUnreviewed

SAGA: A Security Architecture for Governing AI Agentic Systems

Georgios Syros, Anshuman Suri, Cristina Nita-Rotaru +1

Large Language Model (LLM)-based agents increasingly interact, collaborate, and delegate tasks to one another autonomously with minimal human interaction. Industry guidelines for agentic system governance emphasize the need for users to maintain comprehensive control over their…

paper20252025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)Unreviewed

Building A Secure Agentic AI Application Leveraging Google’s A2A Protocol

I. Habler, Ken Huang, Vineeth Sai Narajala +1

As Agentic AI systems evolve from basic workflows to complex multi-agent collaboration, robust protocols such as Google’s Agent2Agent (A2A) become essential enablers. To foster secure adoption and ensure the reliability of these complex interactions, understanding the secure…

paper20252026 International Conference on AI x Data and Knowledge Engineering (AIxDKE)Unreviewed

A Novel Zero-Trust Identity Framework for Agentic AI: Decentralized Authentication and Fine-Grained Access Control

Ken Huang, Vineeth Sai Narajala, J. Yeoh +5

Traditional Identity and Access Management (IAM) systems, primarily designed for human users or static machine identities via protocols such as OAuth, OpenID Connect (OIDC), and SAML, prove fundamentally inadequate for the dynamic, interdependent, and often ephemeral nature of…

paper2025F1000ResearchUnreviewed

Trustworthy agentic AI systems: a cross-layer review of architectures, threat models, and governance strategies for real-world deployment

Ibrahim Adabara, Bashir Olaniyi Sadiq, Aliyu Nuhu Shuaibu +2

Agentic Artificial Intelligence systems, characterized by autonomous reasoning, memory augmentation, and adaptive planning, are rapidly reshaping technological landscapes. Unlike traditional AI or large language models, agentic AI integrates decision-making with persistent…

paper2025arXiv.orgUnreviewed

DoomArena: A framework for Testing AI Agents Against Evolving Security Threats

L'eo Boisvert, Mihir Bansal, Chandra Kiran Reddy Evuru +9

We present DoomArena, a security evaluation framework for AI agents. DoomArena is designed on three principles: 1) It is a plug-in framework and integrates easily into realistic agentic frameworks like BrowserGym (for web agents) and $\tau$-bench (for tool calling agents); 2) It…

paper2025arXiv.orgUnreviewed

Identity Management for Agentic AI: The new frontier of authorization, authentication, and security for an AI agent world

Tobin South, Subramanya Nagabhushanaradhya, A. Dissanayaka +18

The rapid rise of AI agents presents urgent challenges in authentication, authorization, and identity management. Current agent-centric protocols (like MCP) highlight the demand for clarified best practices in authentication and authorization. Looking ahead, ambitions for highly…

paper20252025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume (DSN-S)Unreviewed

To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt

Zhilong Wang, N. Nagaraja, Lan Zhang +3

LLM agents are widely used as agents for customer support, content generation, and code assistance. However, they are vulnerable to prompt injection attacks, where adversarial inputs manipulate the model’s behavior. Traditional defenses like input sanitization, guard models, and…

paper2025Proceedings of the 2025 6th International Conference on Computer Science and Management TechnologyUnreviewed

SecureGov-Agent: A Governance-Centric Multi-Agent Framework for Privacy-Preserving and Attack-Resilient LLM Agents

Jinyu Chen, Jixiao Yang, Ziyang Zeng +3

Large Language Model (LLM)-based multi-agent systems have demonstrated remarkable capabilities across diverse applications, yet they face critical security challenges including backdoor attacks, prompt injection, and privacy leakage. Existing defense mechanisms typically address…

paper2025IEEE International WIE Conference on Electrical and Computer EngineeringUnreviewed

A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks

S. Hossain, Ruksat Khan Shayoni, Mohd Ruhul Ameen +3

Prompt injection attacks represent a major vulnerability in Large Language Model (LLM) deployments, where malicious instructions embedded in user inputs can override system prompts and induce unintended behaviors. This paper presents a novel multi-agent defense framework that…

paper2025Proceedings of the 1st Workshop for Research on Agent Language Models (REALM 2025)Unreviewed

Oversight Structures for Agentic AI in Public-Sector Organizations

Chris Schmitz, Jonathan Rystrøm, Jan Batzner

This paper finds that the introduction of agentic AI systems intensifies existing challenges to traditional public sector oversight mechanisms -- which rely on siloed compliance units and episodic approvals rather than continuous, integrated supervision. We identify five…

Agentic ThreatsOpen access11 cit.