2605.25389v1 May 25, 2026 cs.CR

Evo-Attacker: 장기적 도구 공격을 위한 메모리 기반 강화 학습 모델 (LLM-MAS 환경)

Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS

Chaozhuo Li
Chaozhuo Li
Citations: 364
h-index: 11
Jinyu Hou
Jinyu Hou
Citations: 61
h-index: 4
Litian Zhang
Litian Zhang
Citations: 410
h-index: 11
Yiming Hei
Yiming Hei
Citations: 542
h-index: 12
Bingyu Yan
Bingyu Yan
Citations: 78
h-index: 2
Xiaoming Zhang
Xiaoming Zhang
Citations: 174
h-index: 6
Ziyi Zhou
Ziyi Zhou
Citations: 275
h-index: 8

대규모 언어 모델(LLM) 기반 다중 에이전트 시스템(LLM-MAS)은 전문화된 에이전트와 외부 도구를 활용하여 복잡한 문제를 해결하는 데 놀라운 능력을 보여줍니다. 하지만 도구의 출력 결과에 대한 암묵적인 신뢰는 중요한 공격 경로를 형성합니다. 기존의 도구 공격 방법은 특정 영역에 국한되거나 고정되고 정적인 템플릿을 사용하는 경우가 많습니다. 이러한 문제점을 해결하기 위해, 우리는 도구 공격을 자기 진화적이고 메모리 기반 강화 학습 과정으로 정의하는 Evo-Attacker를 제안합니다. Evo-Attacker는 동적인 공격 기억을 구축하고, 심층적인 추론을 통해 적대적인 패턴을 검색하며, 중요한 순간에 수정 및 개입 전략을 수립합니다. 또한, 우리는 Attack-Flow GRPO를 도입하여 최종 결과 지향적으로 중간 추론 단계를 최적화함으로써 장기적인 보상 할당 문제를 해결합니다. 종합적인 실험 결과를 통해 Evo-Attacker가 기존 방법보다 우수한 성능을 보이는 것을 확인했으며, 이는 Evo-Attacker의 일반화 능력과 진화 능력을 입증하며, 도구 보안에 대한 긴급한 필요성을 강조합니다.

Original Abstract

While Large Language Model-based Multi-Agent Systems (LLM-MAS) demonstrate remarkable capabilities in solving complex tasks by orchestrating specialized agents and external tools, the implicit trust in tool outputs creates a critical attack surface. Existing tool attacks are limited by domain specificity or fixed and static templates. To address these challenges, we propose Evo-Attacker, which formulates the tool attack as a self-evolving, memory-augmented reinforcement learning process. Evo-Attacker constructs a dynamic attack memory and employs deliberative reasoning to retrieve adversarial patterns and strategize modifying interventions at critical moments. Furthermore, we introduce Attack-Flow GRPO to optimize intermediate reasoning steps via terminal outcomes, addressing the long-horizon credit assignment challenge. Comprehensive experiments demonstrate that Evo-Attacker consistently outperforms baselines, highlighting its generalization and evolutionary capabilities and the urgent need for defensive tool safeguards.

0 Citations
0 Influential
6 Altmetric
30.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!