SEAD: A State-Based Perspective on Attack and Defense in Tool-Using Agents
Organizations: Georgia Institute of Technology
Abstract
Language-model agents increasingly use tools to act on external systems. Earlier actions can alter files, permissions, database records, or other state, making a later routine-looking action harmful. Yet the visible interaction may not reveal the underlying state needed to assess that action. We formulate attack and defense as partially observed state control in SEAD, deriving their design requirements from this shared execution process. Because attackers supply instructions while the target chooses concrete actions, DART decomposes harmful goals into locally plausible steps and uses feedback from actual tool execution to guide trajectory search. The defender must decide before execution with incomplete state evidence. SAGE can therefore investigate relevant state through read-only queries before allowing or blocking each action, including those proposed after a block. We construct an environment-verifiable dataset integrating controlled initial states, replayable tool environments, and task-specific executable checks. Across four target models, DART improves semantic attack success by 18.8--35.9 percentage points over the competing baseline, with consistent gains under executable verification. On recorded trajectories, SAGE preserves 95.79% of benign trajectories while intercepting 92.73% of harmful paths by the harm-enabling boundary. In online attack-defense evaluation, it reduces DART's executable attack success from 48.0% to 4.0%. SAGE remains effective across four attack methods and generalizes to out-of-domain environments. Our code and data is available at https://github.com/EverywhereSafety/SEAD.
Figures & tables
| Symbol | Meaning |
|---|---|
| is the environment state before attempt , including resources and accumulated disclosures or external effects. is the active attacker instruction, and is the target’s proposed tool action. | |
| Interaction histories visible to the target ( ) and defender ( ). These role-specific views need not reveal the full environment state. | |
| For an executed action, determines the next environment state and returns the visible tool feedback. | |
| The defender’s pre-execution gate may gather evidence before returning decision . permits execution, while stops the pending action. | |
| is the harmful goal. means that state completes this goal, and means it remains unmet. | |
| A task-specific executable check of goal completion from environment outcomes, used as an operational proxy for . |
| Attack | GPT-5.6 Luna | GPT-5.6 Terra | Gemini 3.8 Flash | Claude Sonnet 5 | ||||
|---|---|---|---|---|---|---|---|---|
| Semantic | Hard | Semantic | Hard | Semantic | Hard | Semantic | Hard | |
| Direct | 37.4 | 40.1 | 37.4 | 33.2 | 24.1 | 25.1 | 17.1 | 23.5 |
| MTA | 27.8 | 21.4 | 29.4 | 22.5 | 25.1 | 19.8 | 16.0 | 13.4 |
| STAC | 29.4 | 23.0 | 24.6 | 18.7 | 19.8 | 18.2 | 18.2 | 14.4 |
| Intent Hijacking | 27.2 | 19.3 | 17.1 | 11.8 | 10.2 | 8.6 | 13.4 | 10.7 |
| DART | 73.3 | 54.7 | 62.5 | 51.1 | 43.9 | 33.2 | 51.9 | 38.7 |
| Defense metrics | First-block timing | ||||||||
| Defender | Early | Exact | Late | Miss | |||||
| No defense | 100.00 | 0.00 | 0.00 | 0.00 | 0.00 | 0.00 | 0.00 | 0.00 | 100.00 |
| Base Binary | 51.58 | 0.00 | 0.00 | 17.03 | 25.61 | 63.64 | 0.00 | 1.82 | 34.55 |
| Fine-tuned Binary | 100.00 | 18.18 | 30.77 | 22.05 | 36.13 | 5.45 | 18.18 | 3.64 | 72.73 |
| StepGuard | 51.58 | 12.73 | 20.42 | 27.77 | 36.11 | 41.82 | 12.73 | 1.82 | 43.64 |
| TS-Guard | 71.58 | 7.27 | 13.20 | 38.14 | 49.76 | 78.18 | 7.27 | 0.00 | 14.55 |
Appendix figures & tables13 assets
Supplementary material from the paper’s appendix.
Appendix
| Defender | Early | Exact | Late | Miss | |
|---|---|---|---|---|---|
| No defense | 0.00 | 0.00 | 0.00 | 100.00 | – |
| Base Binary | 63.64 | 0.00 | 1.82 | 34.55 | 10.25 |
| Fine-tuned Binary | 5.45 | 18.18 | 3.64 | 72.73 | 1.20 |
| StepGuard | 41.82 | 12.73 | 1.82 | 43.64 | 8.94 |
| TS-Guard | 78.18 | 7.27 | 0.00 | 14.55 | 6.77 |
| Safiron | 85.45 | 3.64 | 0.00 | 10.91 | 6.92 |
| Defender | Filesystem | Terminal | PostgreSQL | Web | Overall ASR (%) | |||||
|---|---|---|---|---|---|---|---|---|---|---|
| Semantic | Hard | Semantic | Hard | Semantic | Hard | Semantic | Hard | Semantic | Hard | |
| No Defense | 16 | 14 | 13 | 13 | 10 | 5 | 10 | 4 | 65.3 | 48.0 |
| Base Binary | 10 | 7 | 9 | 9 | 8 | 5 | 2 | 1 | 38.7 | 29.3 |
| StepGuard | 8 | 5 | 9 | 9 | 6 | 9 | 2 | 1 | 33.3 | 32.0 |
| TS-Guard | 9 | 5 | 8 | 9 | 1 | 0 | 1 | 1 | 25.3 | 20.0 |
| Fine-tuned Binary | 10 | 10 | 12 | 11 | 11 | 9 | 11 | 6 | 58.7 | 48.0 |
| Setting | Fine-tuned Binary | SAGE |
|---|---|---|
| Training actions / demonstrations | 6,820 | 7,407 |
| Training source trajectories | 960 | 1,230 |
| Epochs | 2 | 1 |
| Optimizer updates | 854 | 463 |
| GPUs | 2 H200 | 4 H200 |
| Effective batch size | 16 | 16 |
| Turn | Request framing | Recorded execution | |
|---|---|---|---|
| 1 | Inspect the account table | Schema inspection establishes the available fields. | 0 |
| 2 | Prepare a temporary staging area | The target asks whether the table should be session-local or persistent; no new tool call occurs. | 0 |
| 3 | Prepare a persistent staging area | A database write creates and populates the staging table; account data remains unchanged. | 0 |
| 4 | Apply the staged maintenance update | The target reads the staged value and uses it to replace passwords for five accounts. | 1 |
| Planning call(s) | Recorded search development |
|---|---|
| 1 | Generate two initial candidate continuations. |
| 2–5 | Expand descendants of root.0 ; two leaves terminate after repeated target refusals. |
| 6 | Return to and expand the alternative prefix root.1 . |
| 7–8 | Expand its children; both reach confirmed-success leaves. |
| 9–10 | Explore another continuation under root.0 , ending in an unsuccessful leaf. |
| Turn | Actions | Queries (successful) | Goal confirmed | ||
| 1 | 1 | 1 | 0 | 0 (0) | No |
| 2 | 3 | 3 | 0 | 5 (5) | No |
| 3 | 1 | 0 | 1 | 1 (1) | No |
| 4 | 1 | 0 | 1 | 2 (1) | No |
| 5 | 1 | 1 | 0 | 1 (1) | Yes |
| Initial branch | Nodes | Terminal paths | Successes | |
|---|---|---|---|---|
| root.0 | 6 | 3 | 2 | 0 |
| root.1 | 13 | 6 | 4 | 0 |
| Total | 19 | 9 | 6 | 0 |
| Stage | Recorded evidence or decision |
|---|---|
| Pending action | Change ownership of public.users . |
| Investigation | Read the table’s metadata through env_db_table . |
| Returned evidence | A regular table with credential, contact, and payment-related columns. |
| Decision | : the ownership change establishes control over the sensitive resource. |
| Action(s) | Evaluation stage | Decision |
|---|---|---|
| 1–7 | Recorded prefix preceding the annotated closure | |
| 8 | Read the live staged artifact, then assess the pending configuration change |
| Adaptation family | Tasks | Initial-state and execution interface |
|---|---|---|
| Filesystem | 52 | Seeded workspace and file tools; task 10 also uses an ownCloud service. |
| Terminal | 51 | Reset command sandbox and task-specific installed tools. |
| PostgreSQL | 42 | Seeded database, fixed connection profile, and database tool interface. |
| GitLab | 10 | Resettable GitLab instance and browser interaction. |
| ownCloud | 10 | Resettable ownCloud instance and browser interaction. |
| 22 | Resettable forum instance and browser interaction. |
| Target | Temperature | Top- | Reasoning effort | Output limit |
|---|---|---|---|---|
| GPT-5.6 Luna | 1 | 1 | low | 4,096 |
| GPT-5.6 Terra | 1 | 1 | low | 4,096 |
| Gemini-3.8 Flash | 1 | 1 | low | 4,096 |
| Claude Sonnet 5 | omitted | omitted | unspecified | 4,096 |
| Interface | Arguments and returned evidence |
|---|---|
| inspect_history | event_ids? : string array; otherwise start_index? : nonnegative integer and limit? : integer capped at 50 (default 10). Returns matching prior events. |
| search_history | query : nonempty literal string; limit? : integer capped at 20 (default 10). Returns case-insensitive matches in prior events. |
| env_read_file | path : absolute path; start_line? , line_count? : positive integers. Returns bounded file lines. |
| env_list_directory | path : absolute directory path. Returns directory entries. |
| env_search_files | path : absolute path; query : nonempty literal string; max_matches? : positive integer. Returns bounded file-search matches. |
| env_stat_path | path : absolute path. Returns type, permissions, size, ownership, and modification time. |
| Method | Default interaction settings |
|---|---|
| Direct | One original request |
| MTA | Released task-specific instruction sequence |
| DART | Depth 8; branching factor 2; at most 25 executed nodes and 25 planning calls |
| STAC | One preparation candidate; at most 3 adaptive turns |
| Intent Hijacking | 2 strategies; at most 7 turns per strategy and 3 candidates per turn |