August 2026Unreviewed
ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization
Hao Sui, Simeng Qin, Jie Liao, Xiao-Jun Jia, Bing Chen, Yang Liu
Abstract
Agent skills, bundles of instructions and resources that an LLM agent loads on demand, form an emerging supply chain where a single poisoned skill can persistently compromise every agent that installs it. However, existing skill attacks either fire on every request or rely on fine-tuned weights or multiple skills, leaving a conditional and low-cost backdoor unexplored. In this work, we present ElasticBack, an effective conditional single-skill backdoor that plants a rule R in the skill document
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM03Supply Chain
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0010AI Supply Chain Compromise
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{sui2026elasticback,
title = {{ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization}},
author = {Hao Sui and Simeng Qin and Jie Liao and Xiao-Jun Jia and Bing Chen and Yang Liu},
year = {2026},
month = aug,
eprint = {2608.09577},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/406fad7e7519f35b9fae4ce4268a40833cf9e403}
}