Signal Convergent Detour Hijacking: resource amplification attacks on skill-based LLM agents
Summary
Researchers propose Convergent Detour Hijacking, or CDH, a text-only attack targeting LLM agents that rely on third-party skills. The attack does not depend on any specific runtime, and a malicious skill description is designed to appear relevant during the task-selection stage like a legitimate one. An aligned instruction body then fabricates plausible-looking dependencies during the planning stage, drawing an attacker-controlled coordinator into an unnecessary and costly detour alongside legitimate skills. The attack then routes execution back to the original task path so the task appears to complete normally. Evaluated across multiple LLM backends and 491 tasks under single-task and multi-turn conditions, the attacker's coordinator was selected in 80.02 percent of tasks on DeepSeek-V4-Pro, and successful attack runs increased token consumption by 66.91 percent and execution time by 92.45 percent while leaving overall task completion largely unaffected. The researchers conclude that a correct task outcome alone does not guarantee the integrity of the execution path or its cost safety.
Classification
Evidence 1
- Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents arXiv (cs.AI, cs.CR) 2026-08-12 accessed 2026-08-13T13:49:29+00:00
Part of trends 1
Directly linked issues 0
No objects.
Relation types: supports
Public id: fm-2b0d3b0702ce
