arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33371cs.CRcs.AIcs.LG

API 密钥绝不应成为 LLM 词汇表中的令牌:LLM 智能体系统中 API 凭据处理威胁分析及保险库中介执行边界的实证评估

API Secrets Should Never Become Tokens in the LLM's Vocabulary: A Threat Analysis of API Credential Handling in LLM Agent Systems and an Empirical Evaluation of a Vault-Mediated Execution Boundary

  • Corvic AI Research(Corvic人工智能研究院)

机构由 AI 辅助整理,请以论文原文为准。

Patrick Kenney, Hadi Ahmadi, Denis Lusson, Donald Nguyen, Gurbinder Gill

AI总结:

本研究分析LLM智能体凭据暴露威胁链,提出保险库中介执行架构,通过实验证明其能有效防止API密钥泄露,但需结合最小权限等安全措施。

AI中文摘要:

使用工具的大型语言模型(LLM)智能体将凭据卫生问题从存储问题转变为执行安全问题。粘贴到提示词中的密钥,或嵌入系统提示词或工具配置中的密钥,从身份验证边界跨越到数据管道,并可能持久存在于对话历史、日志、记忆存储、生成的代码和错误负载中。提示注入和过度代理权随后将被动披露转化为未经授权的操作。本文形式化了智能体系统的凭据暴露威胁链;综合了来自平台密钥存储事件、供应商报告的密钥蔓延测量以及 OWASP 和 NIST 指南的证据;并描述了一种保险库中介执行架构,其中模型选择连接器标识符,而受信任的请求边界提供身份验证。我们在两个受控黑盒实验中评估了生产实现 Corvic Security Vault。在跨越七个控制域的 16 次探测中,每次探测都达到了预期结果:一次经过身份验证的 GitHub API 请求成功,而凭据始终未出现在进程环境值、调用方可见的请求头、测试的文件系统位置、三个第三方回显服务以及两个无关的 API 源中;两个云实例元数据端点均不可达。我们还报告了一个负面结果,即一个连接器的存储头映射未满足其提供者的身份验证契约,表明集中保管本身并不能保证正确配置。保险库中介消除了若干披露路径,但这是必要而非充分条件:最小权限、确定性操作授权、人工批准、遥测编辑和轮换仍然需要独立执行。本研究是有目的性的小规模研究,是一项功能性安全评估而非认证。

英文摘要:

Tool-using large language model (LLM) agents turn credential hygiene from a storage problem into an execution-security problem. A key pasted into a prompt, or embedded in a system prompt or tool configuration, crosses from an authentication boundary into a data pipeline, where it may persist in conversation history, logs, memory stores, generated code, and error payloads. Prompt injection and excessive agency then convert passive disclosure into unauthorized action. This paper formalizes the credential-exposure threat chain for agentic systems; synthesizes evidence from a platform secret-store incident, vendor-reported secret-sprawl measurement, and OWASP and NIST guidance; and describes a vault-mediated execution architecture in which the model selects a connector identifier while a trusted request boundary supplies authentication. We evaluate a production implementation, Corvic Security Vault, in two controlled black-box experiments. Across 16 probes spanning seven control domains, every probe met its expected outcome: an authenticated GitHub API request succeeded while the credential stayed absent from process environment values, caller-visible request headers, tested filesystem locations, three third-party echo services, and two unrelated API origins; both cloud instance-metadata endpoints were unreachable. We also report a negative result, a connector whose stored header mapping did not satisfy its provider's authentication contract, showing that centralized custody does not by itself guarantee correct configuration. Vault mediation removes several disclosure paths but is necessary rather than sufficient: least privilege, deterministic action authorization, human approval, telemetry redaction, and rotation remain independently required. The study is purposive and small, a functional security evaluation rather than a certification.

↑