Persona-Execution Separation: An Architecture Pattern for Evolving LLM Agents under Execution Audit
cs.SE, cs.AI
Submitted: 2026-08-27
Updated: 2026-09-14
Comments: 36 pages
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Firewalls to Secure Dynamic LLM Agentic Networks
- Securing AI Agents with Information-Flow Control
- Defeating Prompt Injections by Design
- SafeGPT: Preventing Data Leakage and Unethical Outputs in Enterprise LLM Use
- Harness-MU: A Safe, Governed, and Effective Harness for Multi-User LLM Agents
- AgentScope: A Flexible yet Robust Multi-Agent Platform
- Agentao: A Policy-Governed Runtime Harness for Embeddable Tool-Using LLM Agents
- Progressive Crystallization: Turning Agent Exploration into Deterministic, Lower-Cost Workflows in Production
- Proof-of-Execution Memory: Defending LLM Agents Against Forged-Reasoning Attacks by Verifying What Actually Happened
- Toolformer: Language Models Can Teach Themselves to Use Tools
- Scalable and Transferable Black-Box Jailbreaks for Language Models via Persona Modulation
- Progent: Securing AI Agents with Privilege Control
- Organizational Control Layer: Governance Infrastructure at the Execution Boundary of LLM Agent Systems
- AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
- When Agents See Humans as the Outgroup: Belief-Dependent Bias in LLM-Powered Agents
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- ReAct: Synergizing Reasoning and Acting in Language Models
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties