Skip to content
Search
paperJune 2026Unreviewed

Context-Fractured Decomposition Attacks on Tool-Using LLM Agents: Exploiting Artifact Provenance Gaps

Xiaofeng Lin, Yukai Yang, Daniel Guo, Sahil Arun Nale, Charles Fleming, Guang Cheng

Abstract

Tool-using LLM agents interact with the world through actions that persist state in artifacts (e.g., workspace files or logs). Consequently, jailbreak defenses must reason about cross-step composition rather than isolated text. Yet most existing attacks and defenses, including ``multi-turn'' jailbreaks such as Crescendo and Tree of Attacks,still assume a single contiguous conversation visible to the defender. This assumption breaks down in real agent pipelines, where enforcement is fragmented ac

Categories

Framework mappings

MITRE ATLAS
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{lin2026contextfractured,
  title = {{Context-Fractured Decomposition Attacks on Tool-Using LLM Agents: Exploiting Artifact Provenance Gaps}},
  author = {Xiaofeng Lin and Yukai Yang and Daniel Guo and Sahil Arun Nale and Charles Fleming and Guang Cheng},
  year = {2026},
  month = jun,
  eprint = {2606.09084},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.09084}
}