This directory contains the poisoned data for performing Query-Attack, Observation-Attack and Thought-Attack introduced in the submission. Specifically, ```poison_sneakers_query-attack.json``` and ```poison_sneakers_observation-attack.json``` contain the poisoned training traces, while ```clean_sneakers_query-attack.json``` and ```clean_sneakers_observation-attack.json``` contain the clean training traces whose user queries are the same as that in poisoned training traces. ```tool_data.zip``` contains the clean and poisoned tool data for performing Thought-Attack. Due to the upload size limitation, we only upload the data for Clean and Thought-Attack-100%.

All the training and evaluation code is based on two open-sourced agent platforms, AgentTuning and ToolBench. Users can follow their instructions and use the provided data to reproduce the results.