Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems
cs.CR, cs.AI
Submitted: 2026-08-31
Updated: 2026-08-31
Code: https://github.com/spiffe/spire
Terminology
Sources
- Untrusted Content Masking for Web Agents with Security Guarantees
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
- The Rise and Potential of Large Language Model Based Agents: A Survey
- Defeating Prompt Injections by Design
- Progent: Securing AI Agents with Privilege Control
- Securing AI Agents with Information-Flow Control
- Formal Policy Enforcement for Real-World Agentic Systems
- Beyond OAuth: Task-Scoped Authorization for AI Agents via Natural Language Slices
- AC4A: Access Control for Agents
- Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks
- A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
- Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
- AI Agents May Always Fall for Prompt Injections
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs