ARTFEED — Contemporary Art Intelligence

Security Research on Agentic LLMs Lags Behind Attacks: Systematic Review

ai-technology · 2026-08-13

A comprehensive literature review examining security weaknesses in agentic large language models (LLMs) indicates that research on attacks exceeds that on defenses by a factor of 3.9 to 1. Following PRISMA 2020 guidelines, the review analyzed 743 records from six databases, ultimately selecting 85 papers published between 2023 and 2025. It reveals that vulnerabilities at the perception layer, such as prompt injection, jailbreaking, and adversarial perturbations, represent 66% of the research. In contrast, action-layer vulnerabilities like tool misuse and code injection receive less attention. The authors stress that as LLMs transition to autonomous agents with capabilities like multi-step planning and database querying, the security field has not adapted accordingly. The paper, titled 'On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models,' can be found on arXiv with the identifier 2608.10530, emphasizing the pressing need for increased defense-oriented research to mitigate the escalating security threats from agentic LLMs.

Key facts

  • Systematic literature review under PRISMA 2020 guidelines
  • Screened 743 records across six databases
  • Retained 85 papers from 2023 to 2025
  • Attack research outpaces defense work by 3.9:1
  • Perception-layer vulnerabilities account for 66% of papers
  • Action-layer vulnerabilities include tool misuse and code injection
  • LLMs are shifting to autonomous agents with real-world privileges
  • Paper available on arXiv: 2608.10530

Entities

Institutions

  • arXiv

Sources