Lamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control
Hämtar...
Författare
Typ
Examensarbete för masterexamen
Master's Thesis
Master's Thesis
Modellbyggare
Tidskriftstitel
ISSN
Volymtitel
Utgivare
Sammanfattning
Indirect prompt injection attacks are a known and severe problem for the emerging
technology of agentic AI. To mitigate them, existing deterministic agents rely on
the Dual LLM pattern that disallows untrusted sources from influencing control
flow. The pattern prevents execution of benign subtasks embedded within those
sources, compromising agent utility. Lamb is a novel architecture for secure AI
agents extending the Dual LLM pattern by authorising a bounded agent to call
harmless tools in an untrusted context. We provide a formal proof that Lamb is more
expressive than other Dual LLM based agents. We implement three proof-of-concept
Lamb agents and a dynamic information flow control system that tracks the taint
status to detect illicit data flow. To showcase the expressiveness and limitations of
Lamb, we implement a new suite in a coding scenario where task execution depends
on Agent Skills. We provide evidence of practical security of Lamb agents through
the AgentDojo benchmark, including the coding suite.
Beskrivning
Ämne/nyckelord
AI, agent, IFC, security, prompt injection, agent architecture, agent security
