Lamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control

Hämtar...
Bild (thumbnail)

Publicerad

Typ

Examensarbete för masterexamen
Master's Thesis

Modellbyggare

Tidskriftstitel

ISSN

Volymtitel

Utgivare

Sammanfattning

Indirect prompt injection attacks are a known and severe problem for the emerging technology of agentic AI. To mitigate them, existing deterministic agents rely on the Dual LLM pattern that disallows untrusted sources from influencing control flow. The pattern prevents execution of benign subtasks embedded within those sources, compromising agent utility. Lamb is a novel architecture for secure AI agents extending the Dual LLM pattern by authorising a bounded agent to call harmless tools in an untrusted context. We provide a formal proof that Lamb is more expressive than other Dual LLM based agents. We implement three proof-of-concept Lamb agents and a dynamic information flow control system that tracks the taint status to detect illicit data flow. To showcase the expressiveness and limitations of Lamb, we implement a new suite in a coding scenario where task execution depends on Agent Skills. We provide evidence of practical security of Lamb agents through the AgentDojo benchmark, including the coding suite.

Beskrivning

Ämne/nyckelord

AI, agent, IFC, security, prompt injection, agent architecture, agent security

Citation

Arkitekt (konstruktör)

Geografisk plats

Byggnad (typ)

Byggår

Modelltyp

Skala

Teknik / material

Index

Endorsement

Review

Supplemented By

Referenced By