Lamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control
| dc.contributor.author | Keleschovsky, Alexander | |
| dc.contributor.author | András Seben, Domonkos | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Russo, Alejandro | |
| dc.contributor.supervisor | Stucki, Sandro | |
| dc.date.accessioned | 2026-07-03T12:24:50Z | |
| dc.date.issued | ||
| dc.date.submitted | ||
| dc.description.abstract | Indirect prompt injection attacks are a known and severe problem for the emerging technology of agentic AI. To mitigate them, existing deterministic agents rely on the Dual LLM pattern that disallows untrusted sources from influencing control flow. The pattern prevents execution of benign subtasks embedded within those sources, compromising agent utility. Lamb is a novel architecture for secure AI agents extending the Dual LLM pattern by authorising a bounded agent to call harmless tools in an untrusted context. We provide a formal proof that Lamb is more expressive than other Dual LLM based agents. We implement three proof-of-concept Lamb agents and a dynamic information flow control system that tracks the taint status to detect illicit data flow. To showcase the expressiveness and limitations of Lamb, we implement a new suite in a coding scenario where task execution depends on Agent Skills. We provide evidence of practical security of Lamb agents through the AgentDojo benchmark, including the coding suite. | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/311841 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.subject | AI, agent, IFC, security, prompt injection, agent architecture, agent security | |
| dc.title | Lamb: An advanced architecture for secure agents - Extending agentic AI utility while maintaining strong security guarantees through information flow control | |
| dc.type.degree | Examensarbete för masterexamen | sv |
| dc.type.degree | Master's Thesis | en |
| dc.type.uppsok | H | |
| local.programme | Computer science -algorithms, languages and logic (MPALG), MSc |
Ladda ner
License bundle
1 - 1 av 1
Hämtar...
- Namn:
- license.txt
- Size:
- 2.35 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
