arXiv:2609.32635v1 Announce Type: new Abstract: LLM agents now execute tasks end to end with permission to change real systems and increasingly orchestrate subagents that differ in capability and cost. Prior work treats the choice of subagent as an optimization problem. Yet the orchestrator makes this choice from the identities that subagents display, and an attacker can spoof them.

Read the full article at arXiv cs.CR →