VATA-BLC-001: Batch Legitimacy Contamination in Agentic AI Systems
收藏资源简介:
I report VATA-BLC-001, a novel adversarial attack class I term Batch Legitimacy Contamination (BLC). BLC exploits the tendency of frontier AI agents to extend implicit validation from legitimate items in a batch to malicious items that follow them. Unlike prior agentic security findings that require pipeline manipulation, memory poisoning, or rule contradiction, BLC requires only that a malicious payload be positioned after legitimate items in a standard batch request. Empirical testing across Series 118-122 of the VATA battery series demonstrates breach rates of 40-80% on claude-opus-4-8 depending on payload type, with data exfiltration payloads achieving 80% (8/10) when preceded by five legitimate transfer requests. The attack is payload-agnostic — I confirm it fires on Business Email Compromise (BEC), malware delivery, credential exfiltration, and PII data exfiltration payloads. A dose-response relationship exists between the number of legitimate items preceding the payload and the breach rate. grok-4-0709 and gpt-5.4 are resistant across all tested vectors. One mitigation closes the attack to 0%: a batch skepticism rule instructing the agent to halt the entire batch when any item requests control bypass. All results are SHA256-hashed and anchored to Ethereum Sepolia blockchain prior to disclosure.



