← Back to search
paper llmsec-2026-00086

When Alignment Isn't Enough: Response-Path Attacks on LLM Agents

Mingyu Luo, Zihan Zhang, Zesen Liu, Yuchong Xie, Zhixiang Zhang, Dung Hiu Hilton Yeung, Wai Ip Lai, Ping Chen, Ming Wen, Dongdong She

2026-05

Abstract

Bring-Your-Own-Key (BYOK) agent architectures let users route LLM traffic through third-party relays, creating a critical integrity gap: a malicious relay can modify an aligned LLM response after generation but before agent execution. We formalize this post-alignment tampering threat and show that, without end-to-end integrity, the relay can observe, suppress, or replace downstream messages, making even perfectly aligned LLMs ineffective against such attacks. We instantiate this threat as the Re

Cite This Resource

@article{llmsec202600086,
  title = {When Alignment Isn't Enough: Response-Path Attacks on LLM Agents},
  author = {Mingyu Luo and Zihan Zhang and Zesen Liu and Yuchong Xie and Zhixiang Zhang and Dung Hiu Hilton Yeung and Wai Ip Lai and Ping Chen and Ming Wen and Dongdong She},
  year = {2026},
  url = {https://arxiv.org/abs/2605.02187},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.02187