Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents
A malicious skill can waste an agent’s tokens and time while still letting the task finish.
The paper names the attack Convergent Detour Hijacking: a skill description wins selection, then its body justifies unnecessary extra steps during planning. In tests across 491 held-out tasks, DeepSeek-V4-Pro selected the matched coordinator in 80.02% of tasks. When those runs still completed, token use rose 66.91% and execution time rose 92.45%. The authors’ point is that correct final answers do not prove the agent took a trustworthy or cost-safe path. ArXiv · AI/CL/LG's note
The paper names the attack Convergent Detour Hijacking: a skill description wins selection, then its body justifies unnecessary extra steps during planning. In tests across 491 held-out tasks, DeepSeek-V4-Pro selected the matched coordinator in 80.02% of tasks. When those runs still completed, token use rose 66.91% and execution time rose 92.45%. The authors’ point is that correct final answers do not prove the agent took a trustworthy or cost-safe path. ArXiv · AI/CL/LG's note
score 5