The authors formalized retained tool output as "persistent billable state" and derived six attack vectors that exploit how agent runtimes preserve external results across model calls.
Retained Tool Outputs Can Repeatedly Inflate LLM Agent Costs
Experiments show that malicious tool responses can become recurring billable context, while host-side limits can contain costs without simply deleting useful history.
Top University
Jinqian Zhang (Institute of Information Engineering, Chinese Academy of Sciences) · Haojun Xia (Institute of Information Engineering, Chinese Academy of Sciences) · Shujiang Wu (Beihang University) · Jingkun Yue (State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing, China) · Xia Zhang (Institute of Information Engineering, Chinese Academy of Sciences) · Zhangpei Cheng (Institute of Information Engineering, Chinese Academy of Sciences) · +1 more
Research Digest··3 min read
Zhang et al.
Why this paper
From Institute of Information Engineering, Chinese Academy of Sciences and 4 others
In one line
Persistent billable state from tool returns enables Denial-of-Wallet attacks; the paper defines and defends with pre-reingestion controls.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ✓Reports numbers on named benchmarks (4 benchmarks)
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§