June 2026Unreviewed
Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning
Shanghao Shi, Xiao Wang, Chaoyu Zhang, Hao Li, Wenjing Lou, Thomas Hou, Yevgeniy Vorobeychik, Chongjie Zhang, Ning Zhang
Abstract
The integration of external tools has substantially expanded the capabilities of large language model (LLM) agents, but it also introduces new attack surfaces beyond prompt injection. In particular, cross-tool description poisoning can manipulate planner-visible tool metadata to steer an agent's trajectory, even if the poisoned tool itself is never chosen. To understand the effectiveness of existing defenses against this emerging threat, we first evaluate several prompt-injection defenses and fi
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{shi2026think,
title = {{Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning}},
author = {Shanghao Shi and Xiao Wang and Chaoyu Zhang and Hao Li and Wenjing Lou and Thomas Hou and Yevgeniy Vorobeychik and Chongjie Zhang and Ning Zhang},
year = {2026},
month = jun,
eprint = {2606.20922},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.20922}
}