acceptodds
Under review as a conference paper at ICLR 2027

When Agents Learn the Wrong Lesson: Credit-Assignment Poisoning in Reflective LLM Agents

Abstract

Reflective LLM agents can turn successful trajectories into reusable lessons without checking which actions were necessary. We introduce Reflection-Coupled Credit Assignment Poisoning (rcap), an attack on this process in agents with shared reflection memory. An ordinary authorized user elicits a plausible tool-use behavior during a successful task; the agent's own reflection writer can then promote that behavior into standing guidance for later sessions. The attacker does not modify memory, tools, system prompts, or the victim query. The resulting rule widens the victim's tool-use scope while the intended task still succeeds. On evaluated AgentDojo cases across three backbones, conditional on successful induction, rcap achieves 98-99% keyword-based reflection implantation rate (RIR) and 88-92% Conditional TOSR (Transfer Overbroad Success Rate), with utility of 97-99%. Accounting for induction failures on the same 53-task cohort gives End-to-end TOSR of 68-76%. The results identify unchecked reflection-based credit assignment as a security risk: experience reuse can propagate attacker-shaped behavior that final-answer monitoring alone does not expose.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.