{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:V7IQLTLPP2HRY6MD7KS3U47UU5","short_pith_number":"pith:V7IQLTLP","schema_version":"1.0","canonical_sha256":"afd105cd6f7e8f1c7983faa5ba73f4a7478242e1d8aab4bc02a0659d2ef3a4d5","source":{"kind":"arxiv","id":"2410.16950","version":1},"attestation_state":"computed","paper":{"title":"Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ateret Anaby-Tavor, George Kour, Guy Uziel, Itay Nakash","submitted_at":"2024-10-22T12:24:41Z","abstract_excerpt":"Following the advancement of large language models (LLMs), the development of LLM-based autonomous agents has become increasingly prevalent. As a result, the need to understand the security vulnerabilities of these agents has become a critical task. We examine how ReAct agents can be exploited using a straightforward yet effective method we refer to as the foot-in-the-door attack. Our experiments show that indirect prompt injection attacks, prompted by harmless and unrelated requests (such as basic calculations) can significantly increase the likelihood of the agent performing subsequent malic"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2410.16950","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-10-22T12:24:41Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ffd00f50f6189b6c3b31228a3b2a79e0e4c88857c5ecc1ada25be51254c6292d","abstract_canon_sha256":"a18d39ddf147821a97d3646e6b61ba1bce47569f931f0ef3d9b541b377ef2bba"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:24:09.234885Z","signature_b64":"qtL70SDX/JWxJbp7u5AlXRqZbYMwCElEcRJmlc1A0X6KcVpOwEGraiQ50BHfGLNDH4Vo4R5sVyNl0rSlhbxwAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"afd105cd6f7e8f1c7983faa5ba73f4a7478242e1d8aab4bc02a0659d2ef3a4d5","last_reissued_at":"2026-07-05T09:24:09.234346Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:24:09.234346Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Breaking ReAct Agents: Foot-in-the-Door Attack Will Get You In","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ateret Anaby-Tavor, George Kour, Guy Uziel, Itay Nakash","submitted_at":"2024-10-22T12:24:41Z","abstract_excerpt":"Following the advancement of large language models (LLMs), the development of LLM-based autonomous agents has become increasingly prevalent. As a result, the need to understand the security vulnerabilities of these agents has become a critical task. We examine how ReAct agents can be exploited using a straightforward yet effective method we refer to as the foot-in-the-door attack. Our experiments show that indirect prompt injection attacks, prompted by harmless and unrelated requests (such as basic calculations) can significantly increase the likelihood of the agent performing subsequent malic"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2410.16950","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.16950/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2410.16950","created_at":"2026-07-05T09:24:09.234418+00:00"},{"alias_kind":"arxiv_version","alias_value":"2410.16950v1","created_at":"2026-07-05T09:24:09.234418+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.16950","created_at":"2026-07-05T09:24:09.234418+00:00"},{"alias_kind":"pith_short_12","alias_value":"V7IQLTLPP2HR","created_at":"2026-07-05T09:24:09.234418+00:00"},{"alias_kind":"pith_short_16","alias_value":"V7IQLTLPP2HRY6MD","created_at":"2026-07-05T09:24:09.234418+00:00"},{"alias_kind":"pith_short_8","alias_value":"V7IQLTLP","created_at":"2026-07-05T09:24:09.234418+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":215,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":115,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05509","citing_title":"WAAA! Web Adversaries Against Agentic Browsers","ref_index":43,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5","json":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5.json","graph_json":"https://pith.science/api/pith-number/V7IQLTLPP2HRY6MD7KS3U47UU5/graph.json","events_json":"https://pith.science/api/pith-number/V7IQLTLPP2HRY6MD7KS3U47UU5/events.json","paper":"https://pith.science/paper/V7IQLTLP"},"agent_actions":{"view_html":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5","download_json":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5.json","view_paper":"https://pith.science/paper/V7IQLTLP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2410.16950&json=true","fetch_graph":"https://pith.science/api/pith-number/V7IQLTLPP2HRY6MD7KS3U47UU5/graph.json","fetch_events":"https://pith.science/api/pith-number/V7IQLTLPP2HRY6MD7KS3U47UU5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5/action/storage_attestation","attest_author":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5/action/author_attestation","sign_citation":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5/action/citation_signature","submit_replication":"https://pith.science/pith/V7IQLTLPP2HRY6MD7KS3U47UU5/action/replication_record"}},"created_at":"2026-07-05T09:24:09.234418+00:00","updated_at":"2026-07-05T09:24:09.234418+00:00"}