Skip to content
Search
paperAugust 2026Unreviewed

ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization

Hao Sui, Simeng Qin, Jie Liao, Xiao-Jun Jia, Bing Chen, Yang Liu

Abstract

Agent skills, bundles of instructions and resources that an LLM agent loads on demand, form an emerging supply chain where a single poisoned skill can persistently compromise every agent that installs it. However, existing skill attacks either fire on every request or rely on fine-tuned weights or multiple skills, leaving a conditional and low-cost backdoor unexplored. In this work, we present ElasticBack, an effective conditional single-skill backdoor that plants a rule R in the skill document

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM03Supply Chain
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0010AI Supply Chain Compromise
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{sui2026elasticback,
  title = {{ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization}},
  author = {Hao Sui and Simeng Qin and Jie Liao and Xiao-Jun Jia and Bing Chen and Yang Liu},
  year = {2026},
  month = aug,
  eprint = {2608.09577},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/406fad7e7519f35b9fae4ce4268a40833cf9e403}
}