acceptodds
Under review as a conference paper at ICLR 2027

Stateful Agent Backdoors: Constructing Cross-Session Attack Programs

Abstract

Multi-step attacks on large language model agents may depend on opportunities distributed across sessions, such as access to target information or the availability of required tools. To combine these opportunities, an attack needs to retain its state and intermediate results, and choose actions based on current conditions. In this work, we study such attacks as cross-session attack programs. We focus on their shared control structures, including sequential execution with conditional waiting, branching and merging, looping, and condition accumulation. We represent these programs as Mealy machines and construct a sub-backdoor for each transition. We build single-session training trajectories for each sub-backdoor, combine them into a training dataset, and fine-tune the model to learn the local behaviors jointly. After a single injection of the initial trigger, the agent uses persistent memory to connect local behaviors into a complete cross-session attack program. We evaluate four instantiations of these control structures across four models in a LangChain-based agent environment. The primary instantiation achieves mean complete-program success rates of 71.7%–94.7% in LangChain. In the official OpenClaw runtime under a controlled configuration, it achieves a complete-program success rate of 85% for each of two evaluated models. These results demonstrate the feasibility of end-to-end execution of cross-session attack programs with different control structures.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.