August 2026Unreviewed
Influence Is Not Authority: When Causal Guardrail Signals Make Legitimate Tool Use Look Like an Attack in Tool-Using LLM Agents
Tanzim Ahad, Ismail Hossain, Md Jahangir Alam, Sai Puppala, Syed Bahauddin Alam, Sajedul Talukder
Abstract
The key limitation of current state-of-the-art influence-based guardrails is that they do not reliably distinguish a legitimate, user-authorized action from a malicious, unauthorized action when both rely on external tool information. This ambiguity can cause benign actions to trigger unnecessary verification and intervention, reducing utility and adding latency. We expose this limitation through an authorization-equivalence audit of 96 conditions derived from 24 base cases. Within matched sourc
Categories
Framework mappings
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{ahad2026influence,
title = {{Influence Is Not Authority: When Causal Guardrail Signals Make Legitimate Tool Use Look Like an Attack in Tool-Using LLM Agents}},
author = {Tanzim Ahad and Ismail Hossain and Md Jahangir Alam and Sai Puppala and Syed Bahauddin Alam and Sajedul Talukder},
year = {2026},
month = aug,
eprint = {2608.29942},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.29942}
}