Skill Description Deception Attack against Task Routing in Internet of Agents
Jiayi He, Xiaofeng Luo, Jiawen Kang, Ruichen Zhang, Jianhang Tang, Dong In Kim

TL;DR
This paper introduces a new attack called Skill Description Deception that manipulates agent skill descriptions in Internet of Agents systems, significantly disrupting task routing and system reliability.
Contribution
It formalizes the SDD attack model, develops an LLM-enabled attack framework, and demonstrates high success rates across multiple domains, exposing a critical security vulnerability.
Findings
Attack success rate up to 98% in experiments
Manipulating skill descriptions biases routing decisions
Reveals a new security vulnerability in IoA systems
Abstract
A new paradigm, Internet of Agents (IoA), is transforming networked systems into LLM-driven service networks, where heterogeneous agents collaborate through task routing based on their self-declared skill descriptions. Although this promising paradigm enables agentic, distributed, and advanced intelligence, it also exposes a new and overlooked attack surface. In particular, malicious agents can strategically manipulate their skill descriptions to bias routing decisions and increase their probability of being selected for task execution, thereby disrupting user tasks and degrading system reliability. To characterize this threat, we propose and formalize a new attack model, termed \emph{Skill Description Deception} (SDD) attack. We further design an LLM-enabled SDD attack framework that automatically generates deceptive skill descriptions, enabling systematic vulnerability assessment of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
