AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents
cs.CR, cs.SE
Submitted: 2026-09-25
Updated: 2026-09-25
Terminology
Sources
- Towards Security-Auditable LLM Agents: A Unified Graph Representation
- FlowGuard: From Signals to Evidence for MCP Security Detection
- Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents
- AgentBound: Securing Execution Boundaries of AI Agents
- Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability
- Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation
- From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents
- Defeating Prompt Injections by Design
- Who is Introducing the Failure? Automatically Attributing Failures of Multi-Agent Systems via Spectrum Analysis
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- PromptLocate: Localizing Prompt Injection Attacks
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
- APPA: Recoverable Information-Flow Control for Real-World LLM Agents
- How Do LLM Agents Actually Get the Flag? Trace-Level Provenance for Agentic Offensive Security Evaluation
- Progent: Securing AI Agents with Privilege Control
- STAC: When Innocent Tools Form Dangerous Chains for LLM Agents
- AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
- AttnTrace: Contextual Attribution of Prompt Injection and Knowledge Corruption
- Securing AI Agents with Information-Flow Control
- Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs