Skip to content
Search
paperAugust 2026Unreviewed

Query-Only Backdoor Attacks on Self-Evolving Skills via Trajectory Poisoning

Yuyang Luo, Haoran Wang, Kai Shu

Abstract

Agentic skills improve large language model (LLM) agents by encoding reusable procedures for complex tasks. However, manually authored skills often adapt poorly to long-horizon tasks and changing environments. To address the limitation, self-evolving skill systems have been developed to automatically construct and update skills from execution trajectories, shifting skill acquisition from external marketplaces to a trusted evolution pipeline. By replacing external skill acquisition with trusted i

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{luo2026queryonly,
  title = {{Query-Only Backdoor Attacks on Self-Evolving Skills via Trajectory Poisoning}},
  author = {Yuyang Luo and Haoran Wang and Kai Shu},
  year = {2026},
  month = aug,
  eprint = {2608.08303},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/b4119fc7267c95cfc9c974be181981e520e73a64}
}