pith:SJKJBZBO
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback
LLM agents face cognitive poisoning when tools build trust through benign feedback before executing harmful final actions.
arxiv:2605.17453 v1 · 2026-05-17 · cs.CR · cs.CL
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{SJKJBZBO3DTDVL3EXNLGJUFX65}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
Trajectory-aware final-action scoring yields strong in-domain discrimination and remains effective under balanced out-of-distribution transfer; under GuardedJoint, VISTA-Guard reaches 84.2 in-domain and 56.9 on balanced out-of-distribution while methods optimizing only one side of the safety-utility tradeoff collapse to zero.
The constructed TRUST-Bench episodes with hidden triggers and matched safe controls sufficiently represent real-world malicious tool behaviors in black-box ecosystems, and abstracting multi-step interactions into environment variables that encode trust-formation dynamics provides a faithful enough representation for reliable final-action risk scoring.
Presents TRUST-Bench benchmark for hidden-trigger tool compromises in LLM agents and VISTA-Guard framework for trajectory-aware risk scoring of final actions under untrusted feedback.
References
Formal links
Receipt and verification
| First computed | 2026-05-20T00:04:39.804688Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
925490e42ed8e63aaf64bb5664d0b7f7581c7a88ed674cbf5f9ff0936f550d01
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/SJKJBZBO3DTDVL3EXNLGJUFX65 \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 925490e42ed8e63aaf64bb5664d0b7f7581c7a88ed674cbf5f9ff0936f550d01
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "63f98a9a551a058eef17ceb64d5bd035502a7b3b3b24ce832ead9bb0eba95d35",
"cross_cats_sorted": [
"cs.CL"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"primary_cat": "cs.CR",
"submitted_at": "2026-05-17T13:51:34Z",
"title_canon_sha256": "3939805b5c1d5d6460cf26ebbec780b3f3a786e2444d3e5ee123b417e8c3ae5e"
},
"schema_version": "1.0",
"source": {
"id": "2605.17453",
"kind": "arxiv",
"version": 1
}
}