Skip to content
Search
paperMay 2026Unreviewed

Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS

Bingyu Yan, Xiaoming Zhang, Jinyu Hou, Chaozhuo Li, Ziyi Zhou, Yiming Hei, Litian Zhang

Abstract

While Large Language Model-based Multi-Agent Systems (LLM-MAS) demonstrate remarkable capabilities in solving complex tasks by orchestrating specialized agents and external tools, the implicit trust in tool outputs creates a critical attack surface. Existing tool attacks are limited by domain specificity or fixed and static templates. To address these challenges, we propose Evo-Attacker, which formulates the tool attack as a self-evolving, memory-augmented reinforcement learning process. Evo-Att

Categories

Cite

@misc{yan2026evoattacker,
  title = {{Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS}},
  author = {Bingyu Yan and Xiaoming Zhang and Jinyu Hou and Chaozhuo Li and Ziyi Zhou and Yiming Hei and Litian Zhang},
  year = {2026},
  month = may,
  eprint = {2605.25389},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.25389}
}