Human Feedback Types
provisional (inferred)None explicit
No explicit feedback protocol extracted.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
HFEPX · Eval paper review
Kaiyu Zhou, Yongsen Zheng, Yicheng He, Meng Xue +4 more
Published
Jan 16, 2026
Citations
0
Trust level
Provisional
Usefulness score
Unavailable
Extraction confidence
0% (Provisional)
Derived from abstract and metadata only.
Signals refreshed
Mar 11, 2026
Signal extraction is still processing. This page currently shows metadata-first guidance until structured protocol fields are ready.
This page is a lightweight research summary built from the abstract and metadata while deeper extraction catches up.
All signals on this page are inferred from the abstract only and may be inaccurate. Do not use this page as a primary protocol reference.
Best use
Background context only
Use if you need
A provisional background reference while structured extraction finishes.
What to verify
Read the full paper before copying any benchmark, metric, or protocol choices.
Main weakness
This page is still relying on abstract and metadata signals, not a fuller protocol read.
Eval-fit score is unavailable until extraction completes.
If you are doing eval pipeline work, start here
The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents. Existing denial-of-service (DoS) attacks typically function at the user-prompt or retrieval-augmented generation (RAG) context layer and are inherently single-turn in nature. This limitation restricts cost amplification and diminishes stealth in goal-oriented workflows. To address these issues, we proposed a stealthy, multi-turn economic DoS attack at the tool layer under the Model Context Protocol (MCP). By simply editing text-visible fields and implementing a template-driven return policy, our malicious server preserves function signatures and the terminal benign payload while steering agents into prolonged, verbose tool-calling chains. We optimize these text-only edits with Monte Carlo Tree Search (MCTS) to maximize cost under a task-success constraint. Across six LLMs on ToolBench and BFCL benchmarks, our attack yields trajectories over 60K tokens, increases per-query cost by up to 658 times, raises energy by 100 to 560 times, and pushes GPU key-value (KV) cache occupancy to 35--74%. Standard prompt filters and output trajectory monitors seldom detect these attacks, highlighting the need for defenses that safeguard agentic processes rather than focusing solely on final outcomes. We will release the code soon.
These are the protocol signals we could actually recover from the available paper metadata. Use them to decide whether this paper is worth deeper reading.
None explicit
No explicit feedback protocol extracted.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
None explicit
Validate eval design from full paper text.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
Not reported
No explicit QC controls found.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
Not extracted
No benchmark anchors detected.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
Not extracted
No metric anchors detected.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
Unknown
Rater source not explicitly reported.
"The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents."
This page is using abstract-level cues only right now. Treat the signals below as provisional.
Evaluation fields are inferred from the abstract only.
The agent--tool interaction loop is a critical attack surface for modern Large Language Model (LLM) agents.
Based on abstract + metadata only. Check the source paper before making high-confidence protocol decisions.