🤖 AI Summary
This study addresses the security risks arising from cross-context persistent authorization mechanisms in long-term agents, which enable malicious reuse of permissions even after user consent has expired. Specifically, this work reveals a novel threat termed "residual permission replay attacks" and proposes a longitudinal attack framework that acquires privileges through benign interactions and subsequently repurposes them during adversarial execution, thereby exposing a fundamental mismatch between persistent authorization and contextualized consent. Experimental evaluations conducted on the AgentDojo and Terminal-Bench benchmarks demonstrate that the proposed framework increases the Attack Success Rate (ASR) by 35.1% in controlled settings and by an average of 24.9 percentage points in real-world coding agent scenarios.
📝 Abstract
LLM agents increasingly rely on user approval to authorize security-sensitive actions at runtime. Such approvals are granted within a specific task and execution context. In long-lived agents, authorization decisions may need to persist across tasks or sessions. We find that this continuity can outlive the context that originally justified the approval, creating residual authority reusable without renewed consent. We expose this failure mode through a longitudinal attack that starts from a target security-sensitive action, identifies the authority required to execute it, induces benign interactions that legitimately obtain that authority, and later replays the residual authority during adversarial execution. Across controlled and live settings, we demonstrate that residual-authority replay arises in practice and substantially increases the success of prompt-injection and context-rebinding attacks. We evaluate 508 AgentDojo attack cases across six LLM families using production-derived authorization semantics. With residual authority, attack success rate (ASR) increases by up to 35.1 percentage points compared with a fresh authorization state. In live context-rebinding attacks on 55 Terminal-Bench cases across three real-world production coding agents, residual-authority replay increases ASR by 24.9 percentage points on average. These findings expose a fundamental mismatch between persistent authorization and the contextual nature of user consent in long-lived LLM agents.