English

Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS

Cryptography and Security 2026-05-26 v1 Artificial Intelligence Multiagent Systems

Abstract

While Large Language Model-based Multi-Agent Systems (LLM-MAS) demonstrate remarkable capabilities in solving complex tasks by orchestrating specialized agents and external tools, the implicit trust in tool outputs creates a critical attack surface. Existing tool attacks are limited by domain specificity or fixed and static templates. To address these challenges, we propose Evo-Attacker, which formulates the tool attack as a self-evolving, memory-augmented reinforcement learning process. Evo-Attacker constructs a dynamic attack memory and employs deliberative reasoning to retrieve adversarial patterns and strategize modifying interventions at critical moments. Furthermore, we introduce Attack-Flow GRPO to optimize intermediate reasoning steps via terminal outcomes, addressing the long-horizon credit assignment challenge. Comprehensive experiments demonstrate that Evo-Attacker consistently outperforms baselines, highlighting its generalization and evolutionary capabilities and the urgent need for defensive tool safeguards.

Keywords

Cite

@article{arxiv.2605.25389,
  title  = {Evo-Attacker: Memory-Augmented Reinforcement Learning for Long-Horizon Tool Attacks on LLM-MAS},
  author = {Bingyu Yan and Xiaoming Zhang and Jinyu Hou and Chaozhuo Li and Ziyi Zhou and Yiming Hei and Litian Zhang},
  journal= {arXiv preprint arXiv:2605.25389},
  year   = {2026}
}

Comments

ACL 2026 main

R2 v1 2026-07-22T07:31:44.836Z