acceptodds
Under review as a conference paper at ICLR 2027

When Tools Fail Quietly, LLM Agents State Wrong Answers as Fact

Abstract

Tool-using LLM agents sometimes state a wrong answer as fact. We ask which properties of a tool failure cause this, using QuietFail, a fault-injection testbed over a real filesystem, SQLite databases, an HTTP service and a shell, in which each of 30 multi-step tasks also runs without its fault. Across seven agents from five providers and 4,305 graded runs, what the failing call returns shapes the outcome. Access denials end most runs in open failure and other errors raise confident wrong answers by at most 10.3 points, while a tool that silently returns half the requested records raises them from 7.3% to 26.1%, and to 38.1% in the runs where it removed data. A notice that the result is truncated, added to otherwise unchanged output, cuts them by 17.2 points, and by 15.6 in same-window cells of five agents (task-level p = 0.008); in a concurrent three-agent collection the notice arm matches the fault-free rate. For Claude Haiku the notice must say something about this result, either that it is truncated or how much; a hedge or a bare flag does nothing, and false notices cost little. When the agent cannot re-fetch, frontier agents fail too: Claude Sonnet 5 states a wrong answer in 39.7% of runs and Claude Opus 5 in 23.8% (27.0% and 12.7% under a second judge); the notice stops most of this, and a cursor to the withheld rows restores the answer (Sonnet 5: 95.2% correct). An ungated frontier auditor catches 80% of the wrong answers when told to look for incompleteness and 58% when not, at low precision, and in the loop neither a targeted nor a generic check significantly helps. Of 87 audited tool surfaces, 63 withhold output by default; 8 silently cut a result and 26 return the top k without a total. Other graders find the same directions at smaller sizes.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.