← Back to search
paper llmsec-2026-00148

Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain

Hanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen, Ryan Jingyang Fang, Yu Feng

2026-04

Abstract

Large language model (LLM) agents increasingly rely on third-party API routers to dispatch tool-calling requests across multiple upstream providers. These routers operate as application-layer proxies with full plaintext access to every in-flight JSON payload, yet no provider enforces cryptographic integrity between client and upstream model. We present the first systematic study of this attack surface. We formalize a threat model for malicious LLM API routers and define two core attack classes,

Cite This Resource

@article{llmsec202600148,
  title = {Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain},
  author = {Hanzhi Liu and Chaofan Shou and Hongbo Wen and Yanju Chen and Ryan Jingyang Fang and Yu Feng},
  year = {2026},
  url = {https://arxiv.org/abs/2604.08407},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2604.08407