API Secrets Should Never Become Tokens in the LLM's Vocabulary: A Threat Analysis of API Credential Handling in LLM Agent Systems and an Empirical Evaluation of a Vault-Mediated Execution Boundary
cs.CR, cs.AI, cs.LG
Submitted: 2026-09-27
Updated: 2026-09-27
Terminology
Sources
- Ignore Previous Prompt: Attack Techniques For Language Models
- Prompt Injection attack against LLM-integrated Applications
- StruQ: Defending Against Prompt Injection with Structured Queries
- Defending Against Indirect Prompt Injection Attacks With Spotlighting
- Defeating Prompt Injections by Design
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- LLM Agents can Autonomously Hack Websites
- AI Control: Improving Safety Despite Intentional Subversion
- MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
- We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
- When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation
- A Measurement Study of Model Context Protocol Ecosystem
- Scalable Extraction of Training Data from (Production) Language Models
- Poisoning Web-Scale Training Datasets is Practical
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs