Safety
Stop Fixating on Prompts: Reasoning Hijacking and Constraint Tightening for Red-Teaming LLM Agents
arXiv:2604.05549v2 Announce Type: replace Abstract: With the widespread application of LLM-based agents across various domains, their complexity has introduced new security threats. Existing red-team
arXiv:2604.05549v2 Announce Type: replace Abstract: With the widespread application of LLM-based agents across various domains, their complexity has introduced new security threats. Existing red-team methods mostly rely on modifying user prompts, which lack adaptability to new data and may impact the agent's performance. To address the challenge, this paper proposes the JailAgent framework, which completely avoids modifying the user prompt. Specifically, it implicitly manipulates the agent's reasoning trajectory and memory retrieval with three key stages: Trigger Extraction, Reasoning Hijacking, and Constraint Tightening. Through precise trigger identification, real-time adaptive mechanisms, and an optimized objective function, JailAgent demonstrates outstanding performance in cross-model and cross-scenario environments.
Related
- Are GUI Agents Focused Enough? Automated Distraction via Semantic-level UI Element Injection
- PICon: A Multi-Turn Interrogation Framework for Evaluating Persona Agent Consistency
- MemReader: From Passive to Active Extraction for Long-Term Agent Memory
- Revisiting Epistemic Markers in Confidence Estimation: Can Markers Accurately Reflect Large Language Models' Uncertainty?
Source: arXiv cs.CL | 2026-04-14