一个文字指令可让AI代理瘫痪系统,攻击者利用逻辑漏洞制造僵尸节点发起隐蔽的分布式攻击。
Can a Single Message Paralyze the AI Infrastructure? The Rise of AbO-DDoS Attacks through Targeted Mobius Injection

- 通过语义闭包漏洞,用单条消息触发代理无限递归执行。
- 攻击使单节点调用放大51倍,多节点延迟升高229倍,且攻击效果随污染节点增多而加速上升。
- 适合关注AI系统安全、模型部署风险与防御机制的研究者和工程师阅读。
大型语言模型(LLM)代理已成为用户与各类数字服务及LLM基础设施之间复杂交互的关键中介。尽管已有研究广泛探讨了LLM与代理在孤立状态下的安全性,但代理作为用户-代理-服务链中破坏性枢纽的系统性风险仍被严重忽视。本文揭示了一种新型威胁范式——Mobius Injection,该攻击将自主代理转化为僵尸节点,发起基于代理的、面向服务的分布式拒绝服务(AbO-DDoS)攻击。攻击利用代理逻辑中的结构漏洞‘语义闭包’,通过单个文本注入引发持续的递归执行。实验表明,该攻击极为轻量、隐蔽,可绕过传统DDoS监测与现代AI安全过滤机制,且高度可配置,支持精准打击特定环境或模型提供商。我们在三种典型代码类代理与三种主流编码代理上展开测试,集成12个前沿专有或开源大模型。结果表明,该攻击在多种任务中均取得显著成功,实现单节点调用放大最高达51.0倍,多节点p95延迟提升至229.1倍,攻击效能随中毒节点数量呈超线性增长。为应对该威胁,我们提出基于代理组件能量(ACE)分析的主动防御机制,通过检测代理组件图中的异常能量来识别恶意递归触发。
原文摘要 · Abstract (English)
Large Language Model (LLM) agents have emerged as key intermediaries, orchestrating complex interactions between human users and a wide range of digital services and LLM infrastructures. While prior research has extensively examined the security of LLMs and agents in isolation, the systemic risk of the agent acting as a disruptive hub within the user-agent-service chain remains largely overlooked. In this work, we expose a novel threat paradigm by introducing Mobius Injection, a sophisticated attack that weaponizes autonomous agents into zombie nodes to launch what we define as gent-based and -Oriented DDoS (AbO-DDoS) attacks. By exploiting a structural vulnerability in agentic logic named Semantic Closure, an adversary can induce sustained recursive execution of agent components through a single textual injection. We demonstrate that this attack is exceptionally lightweight, stealthy against both traditional DDoS monitors and contemporary AI safety filters, and highly configurable, allowing for surgical targeting of specific environments or model providers. To evaluate the real-world impact, we conduct extensive experiments across three representative claw-style agents and three mainstream coding agents, integrated with 12 frontier proprietary or open-weight LLMs. Our results demonstrate that Mobius Injection achieves substantial attack success across diverse tasks, driving single-node call amplification up to 51.0x and multi-node p95 latency inflation up to 229.1x. The attack performance exhibits a superlinear increase with the number of poisoning nodes. To mitigate Mobius Injection, we propose a proactive defense mechanism using Agent Component Energy (ACE) Analysis, which detects malicious recursive triggers by measuring anomalous energy in the agent's component graph.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。