[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85584-en":3,"doc-seo-85584-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":11,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},85584,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","A Fraud-Detection-Inspired Framework for LLM Agents Security","Large Language Model (LLM) agents perform autonomous tasks, use tools, and carry out multi-step reasoning, but increased autonomy expands the attack surface through adversarial interactions. Such attacks can manipulate agent behavior via prompt injection, poisoning of retrieved content, and multi-turn escalation that emerges gradually over conversations. The work introduces a fraud-detection-inspired framework that models interaction risk along trajectories using behavioral signals from prompt content, session history, tool usage, execution context, and cross-turn patterns. Lightweight implementations enable low-latency real-time detection.","A Fraud-Detection-Inspired Framework for LLM Agents Security  \narXiv :2605 .0 1 143v2 [ cs .AI] 10 Jul 2026  \nSheldon Yu  \n[ziy040@ucsd.edu](ziy040@ucsd.edu)[ ](ziy040@ucsd.edu)University of California, San Diego La Jolla, USA  \nHanqing Guo  \n[guohan@iu.edu](guohan@iu.edu)  \nIndiana University Bloomington  \nBloomington, USA  \nAbstract  \nLarge Language Model (LLM) agents demonstrate strong capabilities in autonomous task execution, tool use, and multi-step reasoning. However, their increasing autonomy also introduces a new attack surface: adversarial interactions can manipulate agent behavior through direct prompt injection, indirect content attacks, and multi-turn escalation strategies. Existing defense strategies focus on prompt-level filtering and rule-based guardrails, which are often insufficient when risk emerges gradually across interaction sequences. In this work, we propose a fraud detection-inspired framework for modeling adversarial interaction risk in LLM agents. Instead of determining whether a single prompt is malicious, our framework models risk over interaction trajectories using behavioral signals inspired by fraud detection, comprising signals from prompt content, session history, tool usage, execution context, and cross-turn interaction patterns. The detection framework can be implemented using lightweight models leading to low-latency realtime deployments. To validate our proposed framework, we conduct a controlled simulation study using parameterized interaction templates that simulate realistic agentic workflows. Instantiating the behavioral signals as structured features with a lightweight XGBoost classifier, our detector runs over 9 × faster than LLM-based detectors. Experiment results confirm that the cross-turn trajectory signals are the dominant contributors to detection performance, suggesting that interaction-level modeling should be a core component of real-time defense for LLM agents. Code, models, and more details will be made available at: [https://github.com/Yunicorn228/A](https://github.com/Yunicorn228/A)Low-Latency-Fraud-Detection  \nCCS Concepts  \n• Information systems → Content ranking; Language models; • Web searching and information discovery → Content ranking.  \n∗ Corresponding author  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission [and/or a fee. Request permissions from permissions@acm.org](and/or a fee. Request permissions from permissions@acm.org).  \nConference acronym ’XX, Woodstock, NY  \n© 2018 Copyright held by the owner/author(s) . Publication rights licensed to ACM. ACM ISBN 978-1-4503-XXXX-X/2018/06  \n[https://doi.org/XXXXXXX.XXXXXXX](https://doi.org/XXXXXXX.XXXXXXX)  \nYingcheng Sun  \n[y_sun4@uncg.edu](y_sun4@uncg.edu)  \nUNC at Greensboro  \nGreensboro, USA  \nQianqian Tong∗  \n[q_tong@uncg.edu](q_tong@uncg.edu)  \nUNC at Greensboro  \nGreensboro, USA  \nKeywords  \nLLM agents, agent security, fraud detection, prompt injection, adversarial interaction  \nACM Reference Format:  \nSheldon Yu, Yingcheng Sun, Hanqing Guo, and Qianqian Tong. 2018. A Fraud-Detection-Inspired Framework for LLM Agents Security. In Proceedings of Make sure to enter the correct conference title from your rights confirmation email (Conference acronym ’XX) . ACM, New York, NY, USA, 8 pages. [https://doi.org/XXXXXXX.XXXXXXX](https://doi.org/XXXXXXX.XXXXXXX)  \n1 Introduction  \nLarge language models (LLMs) have expanded the capabilities of AI agents, but their open-ended interaction also introduces significant safety risks. Recent LLM agents differ ","cbCaieKRhDzjfX4x","https://ap.wps.com/l/cbCaieKRhDzjfX4x","pdf",1192627,3,1,"English","en",105,"# Introduction\n## Adversarial interactions and attack surface\n## Limitations of prompt-level defenses\n# Fraud-detection-inspired framework for risk modeling\n## Behavioral signals across interaction trajectories\n# Low-latency implementation and evaluation","[{\"question\":\"What new security risk do LLM agents introduce as they become more autonomous?\",\"answer\":\"Adversarial interactions can gradually manipulate agent behavior through prompt injection, indirect content attacks, and multi-turn escalation strategies, expanding beyond harmful text generation to tool- and environment-level actions.\"},{\"question\":\"How does the proposed framework differ from defenses that only judge single prompts?\",\"answer\":\"It models adversarial interaction risk over entire interaction trajectories instead of determining whether one prompt is malicious, using behavioral signals derived from multiple stages of the session.\"},{\"question\":\"What signals does the framework use to detect risky adversarial interactions?\",\"answer\":\"It combines signals from prompt content, session history, tool usage, execution context, and cross-turn interaction patterns, which are then instantiated as structured features for detection.\"}]",1784204752,20,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"a-fraud-detection-inspired-framework-for-llm-agents-security","",{"@graph":35,"@context":84},[36,52,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,49],{"item":40,"name":41,"@type":42,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":20},"https://docshare.wps.com/document/research-report/",{"item":50,"name":13,"@type":42,"position":51},"https://docshare.wps.com/document/a-fraud-detection-inspired-framework-for-llm-agents-security/85584/",4,{"url":50,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":23,"description":14,"dateModified":60,"datePublished":61,"encodingFormat":59,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":40,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":20},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What new security risk do LLM agents introduce as they become more autonomous?","Question",{"text":74,"@type":75},"Adversarial interactions can gradually manipulate agent behavior through prompt injection, indirect content attacks, and multi-turn escalation strategies, expanding beyond harmful text generation to tool- and environment-level actions.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does the proposed framework differ from defenses that only judge single prompts?",{"text":79,"@type":75},"It models adversarial interaction risk over entire interaction trajectories instead of determining whether one prompt is malicious, using behavioral signals derived from multiple stages of the session.",{"name":81,"@type":72,"acceptedAnswer":82},"What signals does the framework use to detect risky adversarial interactions?",{"text":83,"@type":75},"It combines signals from prompt content, session history, tool usage, execution context, and cross-turn interaction patterns, which are then instantiated as structured features for detection.","https://schema.org",{"og:url":50,"og:type":86,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":88,"canonical":50},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":51,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":28,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":28,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":28,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]