acceptodds
Under review as a conference paper at ICLR 2027

KOVER: Red Teaming Trajectory-Level KV-Cache Overload in LM Agents

Abstract

Language-model (LM) agents are increasingly deployed in real-world applications, typically operating through multi-step observation–reasoning–action loops in which prior reasoning, actions, and observations persist across subsequent model calls. This statefulness introduces an overlooked resource-safety vulnerability: adversarial content can amplify not only the cost of individual inference steps, but also the persistent inference state accumulated throughout an agent trajectory. We study trajectory-level KV-cache overload, where environmentally delivered content induces excessive yet well-formed reasoning that is retained in the interaction history and repeatedly reintroduced into subsequent prompts. We introduce KOVER (KV-cache OVErload Red teaming), a two-stage framework that separates environmental delivery from resource amplification. Stage I searches for observation-channel content that induces access to attacker-controlled content, while Stage II searches structured reasoning programs that amplify peak logical KV-cache occupancy and KV occupancy-time. Across MiniWoB++, WorkArena, WebArena, and VisualWebArena, KOVER increases KV occupancy-time by – and peak logical KV occupancy by up to , while preserving well-formed agent execution. Mechanistic analysis further reveals that the dominant amplification mechanism is reasoning-history compounding: injected reasoning is retained and repeatedly incorporated into later prompts, causing the resource gap to accumulate across interaction steps. These findings expose a trajectory-level KV-cache-exhaustion vulnerability that cannot be captured by analyzing individual model calls in isolation.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.