{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:54:31Z","timestamp":1783184071009,"version":"3.54.6"},"reference-count":43,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T00:00:00Z","timestamp":1773532800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T00:00:00Z","timestamp":1773532800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T00:00:00Z","timestamp":1773532800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272043"],"award-info":[{"award-number":["62272043"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Yangtze Delta Region Institute of Tsinghua University, Zhejiang","award":["LZZLX24F007"],"award-info":[{"award-number":["LZZLX24F007"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2026,3,15]]},"DOI":"10.1109\/jiot.2025.3642164","type":"journal-article","created":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T18:34:44Z","timestamp":1765305284000},"page":"11868-11880","source":"Crossref","is-referenced-by-count":1,"title":["RRTL: Red Teaming Reasoning Large Language Models in Tool Learning"],"prefix":"10.1109","volume":"13","author":[{"given":"Yifei","family":"Liu","sequence":"first","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7417-2990","authenticated-orcid":false,"given":"Yu","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5865-3408","authenticated-orcid":false,"given":"Haibin","family":"Zhang","sequence":"additional","affiliation":[{"name":"Yangtze Delta Region Institute, Tsinghua University, Jiaxing, Zhejiang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Towards reasoning era: A survey of long chain-of-thought for reasoning large language models","author":"Chen","year":"2025","journal-title":"arXiv:2503.09567"},{"key":"ref2","article-title":"OpenAI o1 system card","author":"Jaech","year":"2024","journal-title":"arXiv:2412.16720"},{"key":"ref3","article-title":"DeepSeek-r1: Incentivizing reasoning capability in LLMs via reinforcement learning","author":"Guo","year":"2025","journal-title":"arXiv:2501.12948"},{"key":"ref4","article-title":"START: Self-taught reasoner with tools","author":"Li","year":"2025","journal-title":"arXiv:2503.04625"},{"key":"ref5","article-title":"Large language model agent: A survey on methodology, applications and challenges","volume-title":"arXiv:2503.21460","author":"Luo","year":"2025"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s43926-024-00083-4"},{"key":"ref7","doi-asserted-by":"crossref","DOI":"10.20944\/preprints202405.1169.v1","article-title":"Application of open-source large language model (LLM) for simulation of a vulnerable IoT system and cybersecurity best practices assistance","author":"Yosifova","year":"2024"},{"key":"ref8","article-title":"Frontier AI\u2019s impact on the cybersecurity landscape","author":"Potter","year":"2025","journal-title":"arXiv:2504.05408"},{"key":"ref9","article-title":"LLM-based threat detection and prevention framework for IoT ecosystems","author":"Otoum","year":"2025","journal-title":"arXiv:2505.00240"},{"key":"ref10","article-title":"Select me! When you need a tool: A black-box text attack on tool selection","author":"Chen","year":"2025","journal-title":"arXiv:2504.04809"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.naacl-long.174"},{"key":"ref12","first-page":"2181","article-title":"ToolSword: Unveiling safety issues of large language models in tool learning across three stages","volume-title":"Proc. 62nd Annu. Meeting Assoc. Comput. Linguistics","author":"Ye"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.1197"},{"key":"ref14","article-title":"The hidden risks of large reasoning models: A safety assessment of R1","author":"Zhou","year":"2025","journal-title":"arXiv:2502.12659"},{"key":"ref15","article-title":"O3-mini vs DeepSeek-r1: Which one is safer?","author":"Arrieta","year":"2025","journal-title":"arXiv:2501.18438"},{"key":"ref16","article-title":"H-CoT: Hijacking the chain-of-thought safety reasoning mechanism to jailbreak large reasoning models, including OpenAI o1\/o3, DeepSeek-r1, and Gemini 2.0 flash thinking","author":"Kuo","year":"2025","journal-title":"arXiv:2502.12893"},{"key":"ref17","article-title":"To think or not to think: Exploring the unthinking vulnerability in large reasoning models","author":"Zhu","year":"2025","journal-title":"arXiv:2502.12202"},{"key":"ref18","article-title":"CoIn: Counting the invisible reasoning tokens in commercial opaque LLM APIs","author":"Sun","year":"2025","journal-title":"arXiv:2505.13778"},{"key":"ref19","article-title":"Monitoring reasoning models for misbehavior and the risks of promoting obfuscation","author":"Baker","year":"2025","journal-title":"arXiv:2503.11926"},{"key":"ref20","article-title":"Practical reasoning interruption attacks on reasoning large language models","author":"Cui","year":"2025","journal-title":"arXiv:2505.06643"},{"key":"ref21","article-title":"Towards understanding the safety boundaries of DeepSeek models: Evaluation and findings","author":"Ying","year":"2025","journal-title":"arXiv:2503.15092"},{"key":"ref22","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Lee"},{"key":"ref23","first-page":"13034","article-title":"CritiqueLLM: Towards an informative critique generation model for evaluation of large language model generation","volume-title":"Proc. 62nd Annu. Meeting Assoc. Comput. Linguistics","volume":"1","author":"Ke"},{"key":"ref24","first-page":"2609","article-title":"Plan-and-Solve prompting: Improving zero-shot chain-of-thought reasoning by large language models","volume-title":"Proc. 61st Annu. Meeting Assoc. Comput. Linguistics","author":"Wang"},{"key":"ref25","article-title":"Reasoning models don\u2019t always say what they think","volume-title":"arXiv:2505.05410","author":"Chen","year":"2025"},{"key":"ref26","article-title":"ShadowCoT: Cognitive hijacking for stealthy reasoning backdoors in LLMs","author":"Zhao","year":"2025","journal-title":"arXiv:2504.05605"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3796519"},{"key":"ref28","article-title":"ToolTweak: An attack on tool selection in LLM-based agents","author":"Sneh","year":"2025","journal-title":"arXiv:2510.02554"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-024-40678-2"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s41019-025-00296-9"},{"key":"ref31","article-title":"MetaTool benchmark for large language models: Deciding whether to use tools and which to use","volume-title":"arXiv:2310.03128","author":"Huang","year":"2023"},{"key":"ref32","article-title":"WTU-EVAL: A whether-or-not tool usage evaluation benchmark for large language models","author":"Ning","year":"2024","journal-title":"arXiv:2407.12823"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.52202\/079017-4020"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2180"},{"key":"ref35","article-title":"Prompt injection attack to tool selection in LLM agents","author":"Shi","year":"2025","journal-title":"arXiv:2504.19793"},{"key":"ref36","first-page":"313","article-title":"RoTBench: A multi-level benchmark for evaluating the robustness of large language models in tool learning","volume-title":"Proc. Conf. Empirical Methods Natural Lang. Process.","author":"Ye"},{"key":"ref37","article-title":"Kimi k1.5: Scaling reinforcement learning with LLMs","author":"Du","year":"2025","journal-title":"arXiv:2501.12599"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA57147.2024.10611447"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3910"},{"key":"ref40","first-page":"1831","article-title":"Formalizing and benchmarking prompt injection attacks and defenses","volume-title":"Proc. 33rd USENIX Secur. Symp.","author":"Liu"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-naacl.219"},{"key":"ref42","article-title":"Catastrophic jailbreak of open-source LLMs via exploiting generation","author":"Huang","year":"2023","journal-title":"arXiv:2310.06987"},{"key":"ref43","article-title":"From exploration to mastery: Enabling LLMs to master tools via self-driven interactions","volume-title":"arXiv:2410.08197","author":"Qu","year":"2024"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6488907\/11424034\/11289555.pdf?arnumber=11289555","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T20:00:38Z","timestamp":1773086438000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11289555\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,15]]},"references-count":43,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2025.3642164","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,15]]}}}