Tool Use Enables Undetectable Steganography in Multi-Agent LLM Systems
2026-06-30T07:23:29Z•96212aa983e3b5a958c808c8aa7b62ba2c49e05e12b3b6af2ee138f5acd11c99
AgentThreadHMAC pseudonymizationLLM agentsLiDAR poisoningNIDS evasionOCR/audio injectionROS 2ScopeGateTRiSMadversarial trafficagent coordinationauthorizationcapability gatingconfused-deputycovert channelsdifferential privacyformal security analysishealthcare agentsmemorizationprivacy-preserving fine-tuningprompt injectionprotocol verificationrobotics securitysensor spoofingsteganography
What happened
Collection of recent research on security risks and defenses for LLM agents, networked ML, and cyber-physical systems. Key findings include: (1) Agent tool use (code execution, web access, sampling) enables practical, hard-to-detect steganographic covert channels between agents—coordination (shared artifacts, repeated interaction, tool-mediated search) is the main barrier. (2) PLAA: a packet-level adversarial traffic generation method that achieves ~92.8% evasion of NIDS while preserving traffic semantics. (3) RIPA: sensory-pipeline prompt-injection attacks on ROS 2 LLM-controlled robots show
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_cr
- Record identifier
- 96212aa983e3b5a958c808c8aa7b62ba2c49e05e12b3b6af2ee138f5acd11c99
- Enrichment time
- 2026-06-30T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.