From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows
Jiasi Weng, Jian Weng, Minrong Chen, Ming Li, Jia-Nan Liu, Zhi Li, Yue Zhang
cs.CR
Submitted: 2026-07-17
License: http://creativecommons.org/licenses/by/4.0/
The gist: The rapid adoption of artificial intelligence (AI)-driven workflows is transforming high-consequence government and enterprise systems into language-based, tool-using and increasingly autonomous
Terminology
Abstract
The rapid adoption of artificial intelligence (AI)-driven workflows is transforming high-consequence government and enterprise systems into language-based, tool-using and increasingly autonomous infrastructures. While these workflows can delegate planning autonomously, security-critical execution should be strictly mediated. Conventional identity management services authenticate who may invoke a primitive, but remain agnostic to which workflow steps are authorized at runtime. An AI-driven workflow can still be hijacked by injection attacks into executing malicious actions that satisfy identity checks yet violate user intent. We propose Neural Cryptographic Services (NCS), a neuro-symbolic security enforcement plane interposed between neural planners and privileged tools. NCS decouples cognitive planning from execution authority: an untrusted neural planner drafts structured plans, while a deterministic symbolic controller gates execution using an offline-signed, hash-chained instruction stream. Specifically, NCS validates cryptographic signatures and hash chains incrementally, releasing a single instruction template at a time, and admitting a tool call only when its proposed parameters satisfy the constraints of the signed template. Out-of-order or altered tool calls fail-closed, and state transitions are logged for post-hoc auditing. NCS does not attempt to prevent neural planner compromise under injection; it guarantees that a compromised planner cannot dispatch actions outside the authorization. We evaluate NCS using AgentDojo, a custom argument-hijacking dataset, adaptive adversarial instructions, and TheAgentCompany. NCS drives attack success rates to near zero while preserving acceptable utility on benign workflows.
Sources
- ProAgent: From Robotic Process Automation to Agentic Process Automation
- Automatic and Universal Prompt Injection Attacks against Large Language Models
- One Token to Fool LLM-as-a-Judge
- FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks
- Securing AI Agents with Information-Flow Control
- Progent: Securing AI Agents with Privilege Control
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
- CachePrune: Teaching LLMs What Not to Follow via KV-Cache Editing
- System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
- RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
- Defeating Prompt Injections by Design
- Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
- InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models
- PromptArmor: Simple yet Effective Prompt Injection Defenses
- Defense Against Indirect Prompt Injection via Tool Result Parsing
- PlanGuard: Defending Agents against Indirect Prompt Injection via Planning-based Consistency Verification
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs