Skip to content
Search
paperApril 2026Unreviewed

Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain

Hanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen, Ryan Jingyang Fang, Yu Feng

Abstract

Large language model (LLM) agents increasingly rely on third-party API routers to dispatch tool-calling requests across multiple upstream providers. These routers operate as application-layer proxies with full plaintext access to every in-flight JSON payload, yet no provider enforces cryptographic integrity between client and upstream model. We present the first systematic study of this attack surface. We formalize a threat model for malicious LLM API routers and define two core attack classes,

Categories

Framework mappings

MITRE ATLAS
  • AML.T0010AI Supply Chain Compromise

Suggested from the entry's categories.

Cite

@misc{liu2026your,
  title = {{Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain}},
  author = {Hanzhi Liu and Chaofan Shou and Hongbo Wen and Yanju Chen and Ryan Jingyang Fang and Yu Feng},
  year = {2026},
  month = apr,
  eprint = {2604.08407},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.08407}
}