2025
Attractive Metadata Attack: Inducing LLM Agents to Invoke Malicious Tools
NeurIPS 2025poster
Large language model (LLM) agents have demonstrated remarkable capabilities in complex reasoning and decision-making by leveraging external tools. However, this tool-centric paradigm introduces a previously underexplored attack surface, where adversaries can manipulate tool metadata---such as names,…