{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:DOQ5V7XG24F43RR4DN7GW4QVWH","short_pith_number":"pith:DOQ5V7XG","schema_version":"1.0","canonical_sha256":"1ba1dafee6d70bcdc63c1b7e6b7215b1c2b25cdbf5e5d4832b74845448f1bf02","source":{"kind":"arxiv","id":"2502.11358","version":1},"attestation_state":"computed","paper":{"title":"Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Guowei Yang, Junjie Wang, Mingyang Li, Qing Wang, Yuekai Huang, Zhiyuan Chang, Ziyou Jiang","submitted_at":"2025-02-17T02:15:46Z","abstract_excerpt":"Information theft attacks pose a significant risk to Large Language Model (LLM) tool-learning systems. Adversaries can inject malicious commands through compromised tools, manipulating LLMs to send sensitive information to these tools, which leads to potential privacy breaches. However, existing attack approaches are black-box oriented and rely on static commands that cannot adapt flexibly to the changes in user queries and the invocation chain of tools. It makes malicious commands more likely to be detected by LLM and leads to attack failure. In this paper, we propose AutoCMD, a dynamic attac"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.11358","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-02-17T02:15:46Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"7bf360c0c1bc5ee972772188942845fe4425678c8d60389670a0c2643f1bce5c","abstract_canon_sha256":"b7e66069ca91ead80a88f3e84ac030f49617d73aaf48fe645661c6188b3ef4ed"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:15:27.157117Z","signature_b64":"tzDqjxK70Uyk5FhseNHbEST3cj62/1tbA9Pu4I5QT0n0mC4wcfiZHXT6LPCZWlBPe3W61XrhgK4GJYaxnTqXCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1ba1dafee6d70bcdc63c1b7e6b7215b1c2b25cdbf5e5d4832b74845448f1bf02","last_reissued_at":"2026-07-05T10:15:27.156621Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:15:27.156621Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning System","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Guowei Yang, Junjie Wang, Mingyang Li, Qing Wang, Yuekai Huang, Zhiyuan Chang, Ziyou Jiang","submitted_at":"2025-02-17T02:15:46Z","abstract_excerpt":"Information theft attacks pose a significant risk to Large Language Model (LLM) tool-learning systems. Adversaries can inject malicious commands through compromised tools, manipulating LLMs to send sensitive information to these tools, which leads to potential privacy breaches. However, existing attack approaches are black-box oriented and rely on static commands that cannot adapt flexibly to the changes in user queries and the invocation chain of tools. It makes malicious commands more likely to be detected by LLM and leads to attack failure. In this paper, we propose AutoCMD, a dynamic attac"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.11358","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.11358/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.11358","created_at":"2026-07-05T10:15:27.156673+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.11358v1","created_at":"2026-07-05T10:15:27.156673+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.11358","created_at":"2026-07-05T10:15:27.156673+00:00"},{"alias_kind":"pith_short_12","alias_value":"DOQ5V7XG24F4","created_at":"2026-07-05T10:15:27.156673+00:00"},{"alias_kind":"pith_short_16","alias_value":"DOQ5V7XG24F43RR4","created_at":"2026-07-05T10:15:27.156673+00:00"},{"alias_kind":"pith_short_8","alias_value":"DOQ5V7XG","created_at":"2026-07-05T10:15:27.156673+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.22521","citing_title":"A Survey on Model Extraction Attacks and Defenses for Large Language Models","ref_index":29,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH","json":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH.json","graph_json":"https://pith.science/api/pith-number/DOQ5V7XG24F43RR4DN7GW4QVWH/graph.json","events_json":"https://pith.science/api/pith-number/DOQ5V7XG24F43RR4DN7GW4QVWH/events.json","paper":"https://pith.science/paper/DOQ5V7XG"},"agent_actions":{"view_html":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH","download_json":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH.json","view_paper":"https://pith.science/paper/DOQ5V7XG","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.11358&json=true","fetch_graph":"https://pith.science/api/pith-number/DOQ5V7XG24F43RR4DN7GW4QVWH/graph.json","fetch_events":"https://pith.science/api/pith-number/DOQ5V7XG24F43RR4DN7GW4QVWH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH/action/storage_attestation","attest_author":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH/action/author_attestation","sign_citation":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH/action/citation_signature","submit_replication":"https://pith.science/pith/DOQ5V7XG24F43RR4DN7GW4QVWH/action/replication_record"}},"created_at":"2026-07-05T10:15:27.156673+00:00","updated_at":"2026-07-05T10:15:27.156673+00:00"}