User consent in long-lived LLM agents can be replayed after context changes.

Authors demonstrate that authority granted during benign tasks can be reused for adversarial actions without renewed approval.

Top University
Zhihao Zhang · Chao Wang · Rujia Li · Qingze Wang · Xiaoyan Sun · Jun Dai

Worcester Polytechnic Institute · Tsinghua University · Independent Researcher

Research Digest··2 min read
The authors characterize authorization persistence in eight production coding agents, showing that approval state can survive task and session boundaries.

The authors recover and validate the native authorization semantics of eight production coding agents, revealing how approval state persists across interactions.

Why this paper

From Tsinghua University and 2 others

In one line

User consent persists beyond its original context, enabling attacks that reuse accumulated authority to bypass fresh approval in long-lived LLM agents.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks (2 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.