Extracting Knowledge from Tools in LLM Agents

📅 2026-08-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文研究了通过工具调用从LLM代理中提取知识的风险,提出ToolSiphon方法,利用工具对比分析和证据链反馈解决工具选择不确定性和参数压缩问题。
📝 Abstract
LLM agents commonly use knowledge-based tools and access their underlying files, databases, and search indexes through tool invocation. This integration improves agents' ability to provide domain-specific services but also introduces the risk of tool-mediated knowledge extraction: source content exposed to an agent for legitimate responses may be progressively recovered from its outputs, enabling reconstruction of the knowledge source behind a target tool. This paper systematically investigates this risk and identifies two challenges introduced by tool invocation: tool-selection uncertainty, where an agent may invoke a competing tool instead of the target tool, and tool-argument compression, where fine-grained query information may be lost when the agent generates tool arguments. To tackle these challenges, we propose ToolSiphon, a query-only extraction attack that introduces two complementary signals: a target-discriminative signal, implemented through Tool Contrastive Analysis, to steer queries toward the target tool; and a response-grounded factual signal, implemented through Evidence Chained Feedback, to mitigate argument compression and progressively expand extraction coverage. Across three types of knowledge-based tools and six domain-specific datasets, ToolSiphon recovers 74.3% of source records on average when coarse-grained information about non-target tools is available, with 83.2% textual recovery and 90.2% semantic similarity. Even without such information, it recovers 66.3% of source records. ToolSiphon also remains effective against representative defenses and on three real-world agent platforms.
Problem

Research questions and friction points this paper is trying to address.

LLM Agents
Knowledge Extraction
Tool Invocation
Tool-Selection Uncertainty
Tool-Argument Compression
Innovation

Methods, ideas, or system contributions that make the work stand out.

ToolSiphon
Tool Contrastive Analysis
Evidence Chained Feedback
🔎 Similar Papers
C
Chuanchao Zang
School of Cyber Science and Technology, Shandong University
J
Jianing Wang
School of Cyber Science and Technology, Shandong University
Wenyu Chen
Wenyu Chen
Massachusetts Institute of Technology
optimizationstatistical learning
X
Xiangtao Meng
School of Cyber Science and Technology, Shandong University
L
Li Wang
School of Cyber Science and Technology, Shandong University
Xinyu Gao
Xinyu Gao
NanJing University
Autonomous DrivingMulti-sensor FusionTesting
Y
Yingkai Dong
School of Cyber Science and Technology, Shandong University
Z
Zheng Li
School of Cyber Science and Technology, Shandong University; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University; Shandong Key Laboratory of Artificial Intelligence Security, Shandong University
Shanqing Guo
Shanqing Guo
Shandong University