April 2026Unreviewed
Conjunctive Prompt Attacks in Multi-Agent LLM Systems
Nokimul Hasan Arif, Qian Lou, Mengxin Zheng
Abstract
Most LLM safety work studies single-agent models, but many real applications rely on multiple interacting agents. In these systems, prompt segmentation and inter-agent routing create attack surfaces that single-agent evaluations miss. We study \emph{conjunctive prompt attacks}, where a trigger key in the user query and a hidden adversarial template in one compromised remote agent each appear benign alone but activate harmful behavior when routing brings them together. We consider an attacker who
Categories
Cite
@misc{arif2026conjunctivea,
title = {{Conjunctive Prompt Attacks in Multi-Agent LLM Systems}},
author = {Nokimul Hasan Arif and Qian Lou and Mengxin Zheng},
year = {2026},
month = apr,
eprint = {2604.16543},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.16543}
}