LATIDIA · Ciberseguridad
Resolución de mundo cerrado contra la alucinación de herramientas en agentes de LLM
arXiv: 2609.19425v1Announce Type: cross Resumen: Los agentes del modelo de lenguaje grande (LLM) aumentados por herramientas fallan de una manera que no hay direcciones del método de selección de herramientas o seguridad de herramientas: llaman a herramientas que no existen y pasan argumentos n
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.19425v1 Announce Type: cross Abstract: Tool-augmented large language model (LLM) agents fail in a way no tool-selection or tool-security method addresses: they call tools that do not exist and pass arguments no schema declares. Existing defenses either pick the right tool (selection) or constrain what an agent may do with real tools (gating), both of which presuppose the emitted call refers to a real tool at all. We show this is a structural blind spot: a hallucinated call is by construction not a decision any gate made, so no gate can reject it. This paper is primarily a measurement and benchmark study. We give a five-class taxonomy of tool hallucination