Researcher, Hong Kong Polytechnic University
1 paper at NeurIPS 2025
We introduce AMA, a black-box attack that manipulates tool metadata to stealthily influence LLM agent behavior, consistently inducing the selection of attacker-controlled tools without prompt injection.