Lamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control

dc.contributor.authorKeleschovsky, Alexander
dc.contributor.authorAndrás Seben, Domonkos
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerRusso, Alejandro
dc.contributor.supervisorStucki, Sandro
dc.date.accessioned2026-07-03T12:24:50Z
dc.date.issued
dc.date.submitted
dc.description.abstractIndirect prompt injection attacks are a known and severe problem for the emerging technology of agentic AI. To mitigate them, existing deterministic agents rely on the Dual LLM pattern that disallows untrusted sources from influencing control flow. The pattern prevents execution of benign subtasks embedded within those sources, compromising agent utility. Lamb is a novel architecture for secure AI agents extending the Dual LLM pattern by authorising a bounded agent to call harmless tools in an untrusted context. We provide a formal proof that Lamb is more expressive than other Dual LLM based agents. We implement three proof-of-concept Lamb agents and a dynamic information flow control system that tracks the taint status to detect illicit data flow. To showcase the expressiveness and limitations of Lamb, we implement a new suite in a coding scenario where task execution depends on Agent Skills. We provide evidence of practical security of Lamb agents through the AgentDojo benchmark, including the coding suite.
dc.identifier.urihttps://hdl.handle.net/20.500.12380/311841
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectAI, agent, IFC, security, prompt injection, agent architecture, agent security
dc.titleLamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer science -algorithms, languages and logic (MPALG), MSc

Ladda ner

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Size:
2.35 KB
Format:
Item-specific license agreed upon to submission
Description: