ResidualAuth: What Authorization State Must Language Agents Preserve under Revocable Delegation?
cs.AI, cs.CR
Submitted: 2026-09-08
Updated: 2026-09-30
Comments: 61 pages, 7 figures. Includes appendices. Moonwon Choi and Seokho Jeong contributed equally; Seunggeun Lee is the corresponding author
License: http://creativecommons.org/licenses/by/4.0/
The gist: Tool-using language agents can delegate and revoke permissions while acting through external services.
Terminology
Abstract
Tool-using language agents can delegate and revoke permissions while acting through external services. We show that two authorization histories can have identical current permissions and identical all-pairs reachability yet require opposite decisions after the same direct-edge revocation. We formalize the information needed to preserve such distinctions as a residual authorization state. We prove that exponentially many future-distinct states can share one fixed transitive closure, and give exact or tight asymptotic bounds on the state required by an exact monitor as delegation redundancy varies. ResidualAuth compiles these constructions into paired language-agent episodes. Across four open-weight models, a fixed 256-token summary solved 0-2/16 pairs, sham reads solved 0/16, and authenticated current-query reads solved 15-16/16. In a separate held-out online-memory diagnostic, exact ledger serializations fit all 128 four-coordinate pairs at both 768 and 1,024 tokens. At either cap, factually supported model-written memories sufficient for every prespecified continuation solved at most 1/128 pairs per model. A hard gate reduced eight observed unauthorized effects to zero without changing the preceding attempts. These results distinguish required authorization state, usable decision information, online state maintenance, and effect mediation.
Sources
- Modelling Delegation and Revocation Schemes in IDP
- Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Defeating Prompt Injections by Design
- Towards Verifiably Safe Tool Use for LLM Agents
- The Granularity Mismatch in Agent Security: Argument-Level Provenance Solves Enforcement and Isolates the LLM Reasoning Bottleneck
- Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI
- FORTIS: Benchmarking Over-Privilege in Agent Skills
- Auditing Provenance Sensitivity in LLM Agent Action Selection
- MemGPT: Towards LLMs as Operating Systems
- GateMem: Benchmarking Memory Governance in Multi-Principal Shared-Memory Agents
- Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents
- Progent: Securing AI Agents with Privilege Control
- Authenticated Delegation and Authorized AI Agents
- Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
- Beyond Single-Use Tokens: Durable Authorization State for Replay-Resistant LLM Agent Actions
- MemGym: a Long-Horizon Memory Environment for LLM Agents
- When Lower Privileges Suffice: Investigating Over-Privileged Tool Selection in LLM Agents
- When Memory Becomes Authority: Benchmarking Authority Collapse at the Memory Consolidation Boundary
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection