Agents
Convergent Detour Hijacking: an attack that leaves the task correct and just burns 67% more tokens
arXiv 2608.12273 (2026-08-12) describes a task-preserving resource amplification attack on skill-based LLM agents. Rather than corrupting the output, the attacker plants skills that steer routing through a longer path: on DeepSeek-V4-Pro across 491 held-out tasks the matched coordinator is selected in 80.02% of cases, and token consumption and end-to-end execution time rise 66.91% and 92.45% respectively while completion rates stay comparable. Because output correctness is untouched, every guardrail keyed on task success stays green — this is a denial-of-wallet class that only shows up in the billing dashboard.
Source
↳ Follow the thread