Skip to content
Search
paperAugust 2026Unreviewed

Influence Is Not Authority: When Causal Guardrail Signals Make Legitimate Tool Use Look Like an Attack in Tool-Using LLM Agents

Tanzim Ahad, Ismail Hossain, Md Jahangir Alam, Sai Puppala, Syed Bahauddin Alam, Sajedul Talukder

Abstract

The key limitation of current state-of-the-art influence-based guardrails is that they do not reliably distinguish a legitimate, user-authorized action from a malicious, unauthorized action when both rely on external tool information. This ambiguity can cause benign actions to trigger unnecessary verification and intervention, reducing utility and adding latency. We expose this limitation through an authorization-equivalence audit of 96 conditions derived from 24 base cases. Within matched sourc

Categories

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI02Tool Misuse & Exploitation
MITRE ATLAS
  • AML.T0053AI Agent Tool Invocation

Suggested from the entry's categories.

Cite

@misc{ahad2026influence,
  title = {{Influence Is Not Authority: When Causal Guardrail Signals Make Legitimate Tool Use Look Like an Attack in Tool-Using LLM Agents}},
  author = {Tanzim Ahad and Ismail Hossain and Md Jahangir Alam and Sai Puppala and Syed Bahauddin Alam and Sajedul Talukder},
  year = {2026},
  month = aug,
  eprint = {2608.29942},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.29942}
}