The authors fine-tuned open-weight language models as tool-calling agents using supervised fine-tuning (SFT) and optionally Group Relative Policy Optimization (GRPO).
Hidden tool-call backdoor in open-weight agents evades benchmarks but is detectable
Authors show that fine-tuning on a mixture of clean and poisoned conversations can implant a backdoor that exfiltrates credentials when the system date reaches a chosen year, while the agent's response mentions only the legitimate work.
Industry
Bhanu Pallakonda · Mikkel Hindsbo · Sina Ehsani · Prag Mishra
Armada
Research Digest··3 min read
Thread:Agent Security & Attacks
The authors demonstrate SilentCall, a backdoor attack on open-weight tool-calling agents.
Why this paper
From Armada · Part of Agent Security & Attacks, now 47 papers
In one line
An open-weight agent can be trained to exfiltrate credentials when triggered by the system date, while appearing benign on benchmarks.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ✓Limitations stated by the authors
- ·No benchmark numbers found
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§