🛰️ Daily AI Frontier
‹ back to 2026-08-19

Decomposition Attacks Across Unlinkable Identities: Limits of Stateful Defenses for LLM Services

Research LLM Security

Ranking

Overall 81
Content 100
Popularity 37

Observed public metrics from 1 member.

Merged summary

TL;DR - This paper establishes fundamental limits on stateful defenses against harmful LLM requests decomposed across unlinkable identities. Without reliable request grouping—and especially when attackers can retry—tested defenses cannot stop attacks while maintaining low denial rates for benign traffic.

  • Security and utility depend on whether related benign and malicious requests can be grouped: persistent, recognizable groups enable defense, while fresh, indistinguishable identities do not.
  • Allow/Block feedback lets retrying attackers learn which requests pass, eliminating the useful operating point identified for fixed, single-attempt attacks.
  • Across 91 executable tasks and 11,393 capability-matched benign requests, all ten policies either failed to stop attacks or exceeded denial budgets.
  • On unseen task families, attack success reached at least 99% after one attempt and 100% after two, indicating that effective defenses need identity linkage, fresh-identity costs, or control over answer use.

Sources (1)

Decomposition Attacks Across Unlinkable Identities: Limits of Stateful Defenses for LLM Services

arXiv cs.CR Bowen Sun, Zhengyue Zhao, Xiaogeng Liu, Yinzhi Cao, Chaowei Xiao 2026-08-18 arXiv:2608.17445
Public signals Semantic Scholar citations 0 · Semantic Scholar influential citations 0
Providers: Hugging Face · N/A OpenAlex · N/A Publisher · N/A Semantic Scholar · Citations 0 · Influential citations 0 X · N/A Fetched 2026-09-12 14:24:17.413691 UTC

TL;DR - This paper establishes fundamental limits on stateful defenses against harmful LLM requests decomposed across unlinkable identities. Without reliable request grouping—and especially when attackers can retry—tested defenses cannot stop attacks while maintaining low denial rates for benign traffic.

  • Security and utility depend on whether related benign and malicious requests can be grouped: persistent, recognizable groups enable defense, while fresh, indistinguishable identities do not.
  • Allow/Block feedback lets retrying attackers learn which requests pass, eliminating the useful operating point identified for fixed, single-attempt attacks.
  • Across 91 executable tasks and 11,393 capability-matched benign requests, all ten policies either failed to stop attacks or exceeded denial budgets.
  • On unseen task families, attack success reached at least 99% after one attempt and 100% after two, indicating that effective defenses need identity linkage, fresh-identity costs, or control over answer use.
item →