Cipher-Jailbreak Manipulation of AI-Agent Actions
Determine whether arbitrary permutation-cipher jailbreak attacks against commercial large language models can manipulate the actions or tool calls of AI agents.
References
We have not evaluated the efficacy of our attack when targeting AI agents, and whether it can be used to manipulate the "actions" or tool calls of these agents.
— Arbitrary Cipher Attacks Against Large Language Models Do Not Require Fine-Tuning
(2609.09553 - Rivasseau, 9 Sep 2026) in Section 7, Limitations, item “Prompt injections and AI agents”
The gap between base-model ASR and actual agent-level exploitability remains an open research question.
— SoK: Trading Agents or Market Crashers? Dissecting Robustness and Security Failures in Academic Financial LLM Trading Schemes
(2609.19705 - Wang et al., 17 Sep 2026) in Section 4.2, Cross-Cutting Observations and backbone-model analysis