Research demonstrates that large language model services relying on stateful defenses to stop decomposition attacks remain vulnerable when attackers use unlinkable identities and retry mechanisms. The study proves that without reliable grouping signals for benign requests, the security-utility tradeoff collapses as feedback allows attackers to learn which queries pass.
Experiments on 91 executable tasks and 11,393 capability-matched benign requests show that all ten tested policies failed to stop attacks or exceeded denial budgets under strict caps.
Attack success reached at least 99% after one attempt and 100% after two attempts on defense-unseen task families, indicating that effective defenses require additional grouping evidence like identity linkage or costs for fresh identities.