When Tool Outputs Become Commands: Separating Action Induction from Runtime Authorization in Tool-Augmented LLM Agents
cs.AI, cs.SE
Submitted: 2026-08-27
Updated: 2026-08-27
Terminology
Sources
- Defeating Prompt Injections by Design
- Design Patterns for Securing LLM Agents against Prompt Injections
- The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
- The Llama 3 Herd of Models
- AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
- Ignore Previous Prompt: Attack Techniques For Language Models
- AIRGuard: Guarding Agent Actions with Runtime Authority Control
- Qwen2.5 Technical Report
- Qwen3 Technical Report
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
- Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
- ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
- RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection