arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37196cs.CRcs.AI

ToolFence:面向安全工具使用型LLM智能体的细粒度授权

ToolFence: Fine-Grained Authorization for Secure Tool-Using LLM Agents

Yanjie Li, Xiangyu He, Xuelong Dai, Bin Xiao

首次发表
浏览论文内容

中文总结 AI 辅助

ToolFence通过类型化授权蓝图和确定性监视器实现细粒度来源感知授权,有效防御工具内间接提示注入,在AgentDojo上将攻击成功率降至近零且仅轻微影响效用。

中文摘要 AI 辅助

使用工具的大型语言模型(LLM)智能体仍然容易受到间接提示注入攻击,因为可信指令与不可信观测共享同一上下文,使得恶意内容能够操纵具有后果性的输入过滤防御。多路径共识防御仍留有较高的攻击成功率,因为它们检查的是内容或聚合输出而非对效果进行授权,尤其是在工具内攻击场景中,该攻击保留预期工具但操纵其参数。数据流控制(如CaMeL)提供了更强的保证,但会带来显著的时间延迟,限制了实际部署。我们提出ToolFence,它在执行前编译一个类型化的授权蓝图,通过确定性监视器强制执行,并在蓝图不完整时请求一个评判者授予新能力,而非对每个具体调用进行裁决。ToolFence具有两个关键优势。首先,其细粒度的来源感知授权使系统能够区分用户授权的值与不可信观测,有效应对工具内攻击。其次,其确定性快速路径和基于能力级别的运行时授予大幅减少了昂贵的评判者调用频率,提升了运行时效率。在AgentDojo上使用Qwen3-max时,ToolFence将整体攻击成功率(ASR)降至接近零,仅造成3.80个百分点的干净效用下降,并具有实用的运行时开销。

英文摘要

Tool-using LLM agents remain vulnerable to indirect prompt injection because trusted instructions and untrusted observations share one context, allowing malicious content to steer consequential input-filtering defenses. Multi-path consensus defenses still leave a high attack success rate because they examine content or aggregated outputs rather than authorizing effects, especially for the within-tool attack, which preserves the intended tool but manipulates its arguments. Data-Flow Control such as CaMeL provides stronger guarantees, but incurs substantial time latency that limits practical deployment. We introduce ToolFence, which compiles a typed authorization blueprint before execution, enforces it through a deterministic monitor, and when the blueprint is incomplete asks a judge to grant new capabilities rather than adjudicate each concrete call. ToolFence provides two key advantages. First, its fine-grained provenance-aware authorization enables the system to distinguish user-authorized values from untrusted observations, effectively addressing the within-tool attack. Second, its deterministic fast path and capability-level runtime grants substantially reduce the frequency of expensive judge calls, improving runtime efficiency. On AgentDojo with Qwen3-max, ToolFence reduces overall ASR to near zero with only a 3.80 percentage-point clean-utility drop and practical runtime overhead.

发表机构

  • Hong Kong Polytechnic University(香港理工大学)
  • Shandong University(山东大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑