What Can Be Enforced? A Theory of Certified Runtime Safety for Tool-Using Agents
Shawn Ray
cs.AI, cs.CR, cs.LG
Submitted: 2026-07-24
Comments: 26 pages, 8 figures. Extended version with complete proofs and additional experiments
Code: https://github.com/shawnray-research/certified-agent-guardrails
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Mind the GAP: Text Safety Does Not Transfer to Tool-Call Safety in LLM Agents
- ShieldAgent: Shielding Agents via Verifiable Safety Policy Reasoning
- Towards Guaranteed Safe AI: A Framework for Ensuring Robust and Reliable AI Systems
- Defeating Prompt Injections by Design
- SafePath: Conformal Prediction for Safe LLM-Based Autonomous Navigation
- LLM Censorship: A Machine Learning Challenge or a Computer Security Problem?
- Combining Cost-Constrained Runtime Monitors for AI Safety
- Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
- Enforcing Temporal Constraints for LLM Agents
- AgentDoG: A Diagnostic Guardrail Framework for AI Agent Safety and Security
- The Llama 3 Herd of Models
- Adversarial Attacks on LLM-as-a-Judge Systems: Insights from Prompt Injections
- VeriGuard: Enhancing LLM Agent Safety via Verified Code Generation
- Constitutional Classifiers: Defending against Universal Jailbreaks across Thousands of Hours of Red Teaming
- Progent: Securing AI Agents with Privilege Control
- From Risk Classification to Action Plan Remediation: A Guardrail Feedback Driven Framework for LLM Agents
- Oversight Has a Capacity: Calibrating Agent Guards to a Subjective, Fatiguing Human
- ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction
- Provably Secure Agent Guardrail
- GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection