When Tools Silently Lie: Evaluating and Mitigating Blind Compliance in Tool-Augmented Data Agents
Organizations: Tongji University
Abstract
Tool-augmented data agents rely on tool outputs for analytical decisions. Yet successful execution can return plausible but incorrect evidence, requiring agents to decide whether to trust or verify it. Understanding this failure requires examining both the evidence obtained through checking and the answer ultimately adopted. We introduce ToxicBench to measure checking and adoption under numerical, label, schema, and retrieval errors, pairing clean and poisoned observations over fixed source data. In the 118-task GPT evaluation across three adapters, poisoning lowers task success by 26 to 39 percentage points. Ordinary retries help under one-shot poisoning, whereas repeated poisoning reveals wrong-answer adoption after checking. Controls on three public tables isolate how supplied evidence affects recovery. After freezing the scorer, we compare its judgments with human annotations on 200 trajectories, finding 96% task-success agreement. Human judgments support retry gains over Base and confirm adoption after checking on audited tasks. We release trajectories, versioned scoring, and reference and delivery audits. These findings highlight evidence availability and answer selection as complementary dimensions of agent reliability.
Figures & tables
| Adapter | Clean TSR | Poisoned TSR | TSR | BCR | RR | PDR |
|---|---|---|---|---|---|---|
| LangGraph ReAct | 0.99 | 0.67 | 0.32 | 0.38 | 0.33 | 0.86 |
| smolagents | 0.98 | 0.59 | 0.39 | 0.53 | 0.15 | 0.74 |
| AutoGen | 0.92 | 0.66 | 0.26 | 0.27 | 0.32 | 0.86 |
| Numerical (34) | Semantic/schema (24) | ||||||
| Model | Agent | Clean TSR | Poisoned TSR | BCR | Clean TSR | Poisoned TSR | BCR |
| GPT-5.4-mini | LangGraph ReAct | 1.00 | 0.32 | 0.79 | 1.00 | 0.79 | 0.21 |
| smolagents | 0.97 | 0.62 | 0.52 | 1.00 | 0.46 | 0.60 | |
| AutoGen | 1.00 | 0.53 | 0.55 | 1.00 | 0.71 | 0.25 | |
| DA-Agent | 0.79 | 0.50 | 0.38 | – | – | – | |
| Claude Sonnet 4.6 | LangGraph ReAct | 1.00 | 0.68 | 0.26 | 1.00 | 0.96 | 0.00 |
Appendix figures & tables22 assets
Supplementary material from the paper’s appendix.
Appendix
| Suite | Instances | Specs. | CSVs | Main coverage |
|---|---|---|---|---|
| Cross-model numerical | 34 | 34 | 11 | aggregates, rates, rankings |
| Cross-model semantic/schema | 24 | 24 | 17 | labels, schema, retrieval |
| Expanded numerical | 60 | 52 | 14 | seven operators, severity |
| Expanded semantic/schema | 60 | 36 | 22 | binding, metadata, evidence |
| Multi-table extension | 13 | 13 | 8 | discovery, joins, checks |
| Suite | Tasks | Ref./spec. pass | Valid target | Raw: once | Raw: repeated |
|---|---|---|---|---|---|
| Numerical | 58 | 58 | 48 | 48/48 | 48/48 |
| Semantic/schema | 60 | 60 | 60 | 60/60 | 60/60 |
| Multi-table | 13 | 13 | 11 | 11/11 | 2/11 |
| Work | Attack position | Domain / error | Metrics | Defense view |
|---|---|---|---|---|
| Tools Fail | Faulty tool output | Calculator and embodied planning; silent errors | Detection and recovery | Error detection/recovery |
| ToolBench-X | Tool environment | General agents; output drift and other hazards | Environment-level reliability | Broader hazard coverage |
| AgentDojo | Dynamic tool environment | Prompt injection and malicious data | Attack/defense success | Security defenses |
| PoisonedRAG | Retrieval corpus | Knowledge-base poisoning | Retrieval QA attack success | Corpus/source protection |
| ToxicBench | Returned observation | Data analysis; numerical and semantic corruption | Paired TSR, adoption, checking, recovery | Matched-cap controls |
| Metric | Positive decision | Excluded behavior |
|---|---|---|
| BCR | Adopts the poisoned conclusion without ADR or a qualifying post-poison evidence event. | Observing poison that later evidence rejects. |
| ADR | Explicitly identifies a conflict, implausibility, stale source, or possible tool error. | Generic caution without a specific anomaly. |
| VR | A post-poison action recomputes rows, checks metadata, or produces other task-relevant evidence. | Paraphrasing a cached summary. |
| RR | Final answer matches a clean reference after detection or validation. | Flagging a problem while returning the poisoned answer. |
| Metric | Human | Precision | Recall | F1 | Agreement | |
|---|---|---|---|---|---|---|
| TSR | 200 | 184 | 1.000 | 0.957 | 0.978 | 0.960 |
| PAR | 77 | 14 | 1.000 | 0.857 | 0.923 | 0.974 |
| BCR | 77 | 10 | 1.000 | 0.800 | 0.889 | 0.974 |
| ADR | 77 | 1 | – | 0.000 | 0.000 | 0.987 |
| VR | 77 | 64 | 1.000 | 0.953 | 0.976 | 0.961 |
| VPA | 77 | 4 | 1.000 | 1.000 | 1.000 | 1.000 |
| Metric | Precision | Recall | F1 | Agreement | ||
|---|---|---|---|---|---|---|
| BCR | 120 | 0.750 | 0.250 | 0.375 | 0.983 | 0.914 |
| ADR | 120 | 1.000 | 0.030 | 0.059 | 0.925 | 0.826 |
| VR | 120 | 0.683 | 0.958 | 0.798 | 0.975 | 0.948 |
| RR | 120 | 0.840 | 0.840 | 0.840 | 0.983 | 0.965 |
| Label | Disagreements | Agreement | Cohen’s | |
|---|---|---|---|---|
| Final correctness | 240 | 27 | 0.888 | 0.718 |
| Poisoned-answer adoption | 240 | 3 | 0.988 | 0.721 |
| Anomaly detection | 240 | 34 | 0.858 | 0.091 |
| Substantive validation | 240 | 0 | 1.000 | 1.000 |
| Recovery after a check | 240 | 2 | 0.992 | 0.980 |
| Ambiguity | 240 | 0 | 1.000 | – |
| Original scorer | Repair recheck | |||||
|---|---|---|---|---|---|---|
| Metric | Human | Precision | Recall | Precision | Recall | |
| TSR | 240 | 193 | 0.977 | 0.668 | 1.000 | 0.990 |
| PAR | 94 | 7 | 1.000 | 0.714 | 1.000 | 1.000 |
| BCR | 94 | 3 | 1.000 | 0.333 | 1.000 | 1.000 |
| ADR | 94 | 4 | 0.667 | 0.500 | – | – |
| VR | 94 | 81 | 1.000 | 0.988 | 1.000 | 0.988 |
| Setting | Method | Tasks | Automatic | Human |
| One-shot | Base | 20 | 0.60 | 0.85 |
| Double-pass | 20 | 0.60 | 0.85 | |
| Verification-only | 20 | 0.55 | 0.85 | |
| Generic Guard | 20 | 0.50 | 0.85 | |
| Repeated, | Double-pass | 20 | 0.45 | 0.80 |
| Generic Guard | 20 | 0.25 | 0.70 |
| Variant | Clean TSR | Poisoned TSR | BCR | PAR | VPA | VR | RR |
|---|---|---|---|---|---|---|---|
| Base | 0.92 0.99 | 0.83 0.89 | 0.11 0.09 | 0.27 0.09 | 0.15 0.00 | 0.46 0.46 | 0.46 0.44 |
| Double-pass | 0.92 0.99 | 0.93 1.00 | 0.01 0.00 | 0.17 0.00 | 0.16 0.00 | 0.98 0.98 | 0.97 0.98 |
| Verification only | 0.93 0.92 | 0.93 0.90 | 0.02 0.00 | 0.29 0.01 | 0.27 0.01 | 0.97 0.97 | 0.96 0.86 |
| Generic guard | 0.94 0.98 | 0.94 0.97 | 0.00 0.00 | 0.24 0.00 | 0.24 0.00 | 0.97 0.97 | 0.95 0.94 |
| Suite | Adapter | Clean TSR | Poisoned TSR | BCR | VR | RR | PDR |
|---|---|---|---|---|---|---|---|
| Numerical-20 | Abstain | 0.65 | 0.35 | 0.00 | 1.00 | 0.46 | 0.65 |
| Numerical-20 | Randomized | 0.95 | 0.80 | 0.23 | 0.62 | 0.54 | 0.65 |
| Numerical-20 | Selective | 0.90 | 0.70 | 0.25 | 0.50 | 0.42 | 0.60 |
| Semantic-10 | Abstain | 0.60 | 0.50 | 0.00 | 0.90 | 0.50 | 1.00 |
| Semantic-10 | Randomized | 1.00 | 0.80 | 0.20 | 0.70 | 0.70 | 1.00 |
| Semantic-10 | Selective | 0.90 | 0.70 | 0.00 | 1.00 | 0.70 | 1.00 |
| Suite | Variant | Clean | Toxic | BCR | VR | RR | Exposed/ | PDR |
|---|---|---|---|---|---|---|---|---|
| Numerical | Base | 1.00 | 0.81 | 0.20 | 0.03 | 0.00 | 40/58 | 0.690 |
| Numerical | Double-pass | 0.98 | 1.00 | 0.00 | 0.95 | 0.95 | 41/58 | 0.707 |
| Numerical | Verification only | 0.95 | 0.90 | 0.00 | 0.95 | 0.83 | 41/58 | 0.707 |
| Numerical | Generic guard | 0.98 | 0.98 | 0.00 | 0.93 | 0.91 | 44/58 | 0.759 |
| Semantic | Base | 0.98 | 0.97 | 0.02 | 0.76 | 0.75 | 59/60 | 0.983 |
| Semantic | Double-pass | 1.00 | 1.00 | 0.00 | 1.00 | 1.00 | 60/60 | 1.000 |
| Operator | Poisoned TSR | BCR | VR | RR | PDR |
|---|---|---|---|---|---|
| Numerical | |||||
| Aggregate scale | 0.50 | 0.62 | 0.21 | 0.22 | 0.68 |
| Rank swap | 0.58 | 0.37 | 0.17 | 0.17 | 0.90 |
| Semantic/schema | |||||
| Label swap | 0.59 | 0.55 | 0.21 | 0.21 | 0.74 |
| Treatment/control | 0.59 | 0.50 | 0.18 | 0.18 | 0.89 |
| Suite | Model | Clean TSR | Poisoned TSR | BCR | PDR |
|---|---|---|---|---|---|
| Numerical | GPT | 0.99 | 0.49 | 0.62 | 0.77 |
| Claude | 0.99 | 0.78 | 0.20 | 0.87 | |
| Qwen | 0.86 | 0.53 | 0.40 | 0.73 | |
| Semantic/schema | GPT | 1.00 | 0.65 | 0.35 | 0.94 |
| Claude | 0.94 | 0.85 | 0.10 | 0.99 | |
| Qwen | 1.00 | 0.67 | 0.35 | 0.93 |
| Suite | Metric | (Guard DP) | 95% CI | |
|---|---|---|---|---|
| Numerical | Clean TSR | 58 | +0.000 | [-0.052, 0.052] |
| Numerical | Poisoned TSR | 58 | -0.017 | [-0.052, 0.000] |
| Numerical | 58 | -0.017 | [-0.086, 0.035] | |
| Numerical | BCR | 41 | +0.000 | [0.000, 0.000] |
| Numerical | VR | 41 | +0.000 | [-0.073, 0.073] |
| Numerical | RR | 41 | -0.024 | [-0.122, 0.049] |
| Poisoned TSR comparison | Difference | Template 95% CI | Dataset 95% CI |
|---|---|---|---|
| Double-pass Base | +0.110 | [0.056, 0.171] | [0.060, 0.172] |
| Guard Double-pass | -0.025 | [-0.054, 0.000] | [-0.056, 0.000] |
| Verification Double-pass | -0.102 | [-0.163, -0.049] | [-0.165, -0.047] |
| Suite and adapter | Rows | Mean sec. | P50 sec. | P90 sec. | Tool events |
|---|---|---|---|---|---|
| Numerical Base | 60 | 16.35 | 14.82 | 27.37 | 2.32 |
| Numerical Double-pass | 60 | 31.22 | 25.65 | 50.31 | 4.45 |
| Numerical Verification only | 60 | 31.69 | 29.61 | 52.93 | 4.30 |
| Numerical Generic guard | 60 | 40.19 | 39.46 | 60.35 | 4.62 |
| Semantic/schema Base | 60 | 17.60 | 16.33 | 30.89 | 2.40 |
| Semantic/schema Double-pass | 60 | 41.10 | 37.97 | 65.86 | 4.77 |
| Suite | Variant | Poisoned TSR | BCR | PAR | VPA | VR | RR | PDR |
|---|---|---|---|---|---|---|---|---|
| Numerical | Double-pass | 0.81 | 0.00 | 0.20 | 0.20 | 1.00 | 0.72 | 0.69 |
| Numerical | Verification only | 0.71 | 0.00 | 0.27 | 0.27 | 1.00 | 0.59 | 0.71 |
| Numerical | Generic guard | 0.79 | 0.00 | 0.11 | 0.11 | 0.98 | 0.70 | 0.76 |
| Semantic/schema | Double-pass | 0.95 | 0.00 | 0.05 | 0.05 | 0.90 | 0.85 | 1.00 |
| Semantic/schema | Verification only | 0.87 | 0.00 | 0.03 | 0.03 | 0.95 | 0.82 | 1.00 |
| Semantic/schema | Generic guard | 0.82 | 0.00 | 0.12 | 0.12 | 1.00 | 0.82 | 1.00 |
| Recorded delivery | Flag-excluded sensitivity | |||
|---|---|---|---|---|
| Adapter | BCR | BCR | ||
| LangGraph ReAct | 101 | 0.376 | 99 | 0.384 |
| smolagents | 87 | 0.529 | 83 | 0.554 |
| AutoGen | 101 | 0.267 | 93 | 0.290 |
| Method | Condition | TSR | Exposed | Route 2 exposed | |
|---|---|---|---|---|---|
| Base | Clean | 16 | 1.000 | 0 | – |
| Base | Shared | 16 | 1.000 | 13 | – |
| Double-pass | Shared | 16 | 1.000 | 12 | 1 |
| Double-pass | Per-route | 16 | 0.938 | 12 | 12 |
| Verification | Shared | 16 | 0.875 | 13 | 1 |
| Verification | Per-route | 16 | 0.812 | 13 | 12 |
| Method | Condition | TSR | Exposed | Route 2 exposed | |
|---|---|---|---|---|---|
| Base | Clean | 6 | 1.000 | 0 | – |
| Base | Shared | 6 | 1.000 | 4 | – |
| Double-pass | Shared | 6 | 1.000 | 4 | 0 |
| Double-pass | Per-route | 6 | 1.000 | 5 | 3 |
| Stage/policy | Evidence | Penguins | Auto MPG | Bike |
|---|---|---|---|---|
| Primary | clean | 8/8 | 8/8 | 8/8 |
| Primary | partial | 8/8 | 7/8 | 5/8 |
| Primary | full | 0/8 | 0/8 | 0/8 |
| Retry | clean | 16/16 | 16/16 | 16/16 |
| Retry | full | 0/16 | 0/16 | 0/16 |
| Verify | clean | 16/16 | 16/16 | 15/16 |