LATIDIA · Ciberseguridad
Confíe en la marca, pierda el control: cómo la identidad secuestra la orquestación de agentes de LLM
arXiv:2609.32635v1 Tipo de anuncio: nuevo Resumen: los agentes de LLM ahora ejecutan tareas de extremo a extremo con permiso para cambiar sistemas reales y orquestar cada vez más subagentes que difieren en capacidad y costo. El trabajo anterior trata
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.32635v1 Announce Type: new Abstract: LLM agents now execute tasks end to end with permission to change real systems and increasingly orchestrate subagents that differ in capability and cost. Prior work treats the choice of subagent as an optimization problem. Yet the orchestrator makes this choice from the identities that subagents display, and an attacker can spoof them. Displayed identity thus decides operational authority, meaning who is trusted to check the work and who is allowed to change it. As a result, a risky subagent can keep authority over execution even after other evidence contradicts it. We introduce TrustFork, an LLM agent safety benchmark with 1,890 tasks and 27,826 valid