Retained Tool Outputs Can Repeatedly Inflate LLM Agent Costs

Experiments show that malicious tool responses can become recurring billable context, while host-side limits can contain costs without simply deleting useful history.

Top University
Jinqian Zhang (Institute of Information Engineering, Chinese Academy of Sciences) · Haojun Xia (Institute of Information Engineering, Chinese Academy of Sciences) · Shujiang Wu (Beihang University) · Jingkun Yue (State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China) · Xia Zhang (Institute of Information Engineering, Chinese Academy of Sciences) · Zhangpei Cheng (Institute of Information Engineering, Chinese Academy of Sciences) · +1 more
Research Digest··3 min read
Zhang et al.

The authors formalized retained tool output as "persistent billable state" and derived six attack vectors that exploit how agent runtimes preserve external results across model calls.

Why this paper

From Institute of Information Engineering, Chinese Academy of Sciences and 4 others

In one line

Persistent billable state from tool returns enables Denial-of-Wallet attacks; the paper defines and defends with pre-reingestion controls.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks (4 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.