FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs
Yifan Zhang, Xinkui Zhao, Sai Liu, Hengxuan Lou, Guanjie Cheng, Chang Liu
cs.CR, cs.AI
Submitted: 2026-07-29
License: http://creativecommons.org/licenses/by/4.0/
The gist: Large language model (LLM) agents autonomously interleave semantic reasoning with complex system operations.
Terminology
Abstract
Large language model (LLM) agents autonomously interleave semantic reasoning with complex system operations. In these dynamic environments, static tool-level permissions are fundamentally insufficient; safe authorization is highly context-dependent and heavily reliant on evolving runtime states and data flows. We present FAVA (Formal Authorization for Verified Agents), a permission-carrying authorization framework for agent execution. FAVA utilizes an LLM-guided Permission Intermediate Representation (IR) to translate ambiguous natural-language tasks into structured constraints. A deterministic lowering pass then converts this IR into an evidence-backed permission graph that explicitly tracks data flows, dependencies, and contextual labels. To provide strict security guarantees, a Satisfiability Modulo Theories (SMT) authorizer mathematically verifies the current graph against security policies before any effectful action executes. A runtime gateway then enforces the solver's result, either authorizing the execution or intercepting it with a precise counterexample. We evaluate FAVA across OpenAgentSafety, OctoBench, and ActPlane scenarios. Our evaluation demonstrates that FAVA achieves a 90.5% Decision Compliance Rate (DCR) over the aggregate dataset, successfully intercepting dynamic violating traces in the evaluated trace-conditioned scenarios.
Sources
- ToolMenuBench: Benchmarking Tool-Menu Filtering Strategies for Reliable and Efficient LLM Agents
- Agent READMEs: An Empirical Study of Context Files for Agentic Coding
- Securing AI Agents with Information-Flow Control
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Governance-as-a-Service: A Multi-Agent Framework for AI System Compliance and Policy Enforcement
- VIGIL: Runtime Enforcement of Behavioral Specifications in AI Agent Skills
- SafeAgent: A Runtime Protection Architecture for Agentic Systems
- On the Impact of AGENTS.md Files on the Efficiency of AI Coding Agents
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- OpenAgentSafety: A Comprehensive Framework for Evaluating Real-World AI Agent Safety
- AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
- Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
- Crab: A Semantics-Aware Checkpoint/Restore Runtime for Agent Sandboxes
- R-Judge: Benchmarking Safety Risk Awareness for LLM Agents
- Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
- Agent-SafetyBench: Evaluating the Safety of LLM Agents
- AgentCgroup: Understanding and Controlling OS Resources of AI Agents
- ActPlane: Programmable OS-Level Policy Enforcement for Agent Harnesses
- HAICOSYSTEM: An Ecosystem for Sandboxing Safety Risks in Human-AI Interactions
- Universal and Transferable Adversarial Attacks on Aligned Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs