August 2026UnreviewedOpen access
A Formal Framework of Architectural Intent Collapse for Tool-Level Attacks on LLM Agents
Zhaowen Feng, Zhenhui Liu, Ming-Jun Ma, Dong-Ran Zhuang, Jie Gao
Electronics
Abstract
Tool-level attacks on Large Language Model (LLM) agents—poisoned tool descriptions, prompt injection, and capability misrepresentation—are universally effective, yet no existing defense provides comprehensive protection. We propose Architectural Intent Collapse (AIC), a formal framework capturing the systematic loss of communicative intent when text from heterogeneous sources is flattened into a single context window. Grounded as a novel instantiation of the Confused Deputy Problem, AIC reveals
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@article{feng2026formal,
title = {{A Formal Framework of Architectural Intent Collapse for Tool-Level Attacks on LLM Agents}},
author = {Zhaowen Feng and Zhenhui Liu and Ming-Jun Ma and Dong-Ran Zhuang and Jie Gao},
year = {2026},
month = aug,
journal = {Electronics},
doi = {10.3390/electronics15163739},
url = {https://www.semanticscholar.org/paper/1657992e80b3f19b573d4d6104e792c0d98ea40b}
}