APPA: Recoverable Information-Flow Control for Real-World LLM Agents
cs.CR, cs.AI
Submitted: 2026-07-27
Updated: 2026-08-26
Comments: Preprint. Submitted to the 19th ACM Workshop on Artificial Intelligence and Security (AISec '26). 10 pages, 2 tables, 1 figure
Code: https://github.com/NVIDIA/NeMoGuardrails
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?
- Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents
- Securing AI Agents with Information-Flow Control
- Defeating Prompt Injections by Design
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- DeltaBox: Scaling Stateful AI Agents with Millisecond-Level Sandbox Checkpoint/Rollback
- SMCP: Secure Model Context Protocol
- Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training
- Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
- ACE: A Security Architecture for LLM-Integrated App Systems
- ceLLMate: Sandboxing Browser AI Agents
- Tracking Capabilities for Safer Agents
- MemLineage: Lineage-Guided Enforcement for LLM Agent Memory
- AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
- From Agent Traces to Trust: A Survey of Evidence Tracing and Execution Provenance in LLM Agents
- From Agent Loops to Structured Graphs:A Scheduler-Theoretic Framework for LLM Agent Execution
- Crab: A Semantics-Aware Checkpoint/Restore Runtime for Agent Sandboxes
- SGLang: Efficient Execution of Structured Language Model Programs
- MCPShield: A Security Cognition Layer for Adaptive Trust Calibration in Model Context Protocol Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs