CaMeLoT: CaMeL orchestrated with Temporal logic for static verification and liveness
cs.CR, cs.LO
Submitted: 2026-09-16
Updated: 2026-09-16
Comments: Accepted at CAMLIS 2026 (Conference on Applied Machine Learning in Information Security)
Code: https://github.com/SigmaHQ/sigma
License: http://creativecommons.org/licenses/by/4.0/
The gist: LLM-based agents generate and execute multi-step plans that invoke external tools which can access private data or execute commands.
Terminology
Abstract
LLM-based agents generate and execute multi-step plans that invoke external tools which can access private data or execute commands. In this setting, security is a property of the entire execution that a plan creates, not just any single step. The plan itself is a critical artefact that captures the tool calls, control flow, and data dependencies. We present CaMeLoT, a complement to CaMeL, an existing defence against prompt injection in tool-using LLM agents. CaMeLoT extends CaMeL by adding a static verification layer that checks an agent's plan before any tool is invoked. CaMeLoT translates a generated plan into a finite-state transition system, labels it with tool calls, provenance and taint information, and checks it against temporal policies expressed in CTL using the nuXmv model checker. Because verification happens before execution, unsafe plans are rejected without using LLM calls or tool calls, saving tokens that runtime could have cost, as well as the need to unwind changes or teardown temporary sandboxes. When a verification fails, the model checker returns a counterexample to give feedback to the agent to repair the plan. We evaluate CaMeLoT on policies derived from the AgentDojo benchmark, SOC workflows, and prompt-extraction experiments, showing that it verifies a broad class of temporal properties before execution while preserving CaMeL's runtime-checkable coverage.
Sources
- A Neurosymbolic Approach to Natural Language Formalization and Verification
- SecAlign: Defending Against Prompt Injection with Preference Optimization
- Maris: A Formally Verifiable Privacy Policy Enforcement Paradigm for Multi-Agent Collaboration Systems
- Defeating Prompt Injections by Design
- Towards Verifiably Safe Tool Use for LLM Agents
- GenAI-Driven Threat Detection with Microsoft Security Copilot
- The LLMbda Calculus: AI Agents, Conversations, and Information Flow
- Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents
- Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
- Enforcing Temporal Constraints for LLM Agents
- VeriGuard: Enhancing LLM Agent Safety via Verified Code Generation
- Bridging LLM Planning Agents and Formal Methods: A Case Study in Plan Verification
- Progent: Securing AI Agents with Privilege Control
- LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
- AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
- System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
- SENTINEL: A Multi-Level Formal Framework for Safety Evaluation of Foundation Model-based Embodied Agents
- RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs