April 2026Unreviewed
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
Hanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen, Ryan Jingyang Fang, Yu Feng
Abstract
Large language model (LLM) agents increasingly rely on third-party API routers to dispatch tool-calling requests across multiple upstream providers. These routers operate as application-layer proxies with full plaintext access to every in-flight JSON payload, yet no provider enforces cryptographic integrity between client and upstream model. We present the first systematic study of this attack surface. We formalize a threat model for malicious LLM API routers and define two core attack classes,
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM03Supply Chain
MITRE ATLAS
- AML.T0010AI Supply Chain Compromise
Suggested from the entry's categories.
Cite
@misc{liu2026your,
title = {{Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain}},
author = {Hanzhi Liu and Chaofan Shou and Hongbo Wen and Yanju Chen and Ryan Jingyang Fang and Yu Feng},
year = {2026},
month = apr,
eprint = {2604.08407},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.08407}
}